Cross-Site Scripting Flaw in AVideo with YPTSocket Plugin
CVE-2026-86188

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86188?

The YPTSocket plugin for AVideo is vulnerable to cross-site scripting, enabling unauthenticated attackers to execute arbitrary JavaScript in users' browsers. This threat arises from the plugin's websocket callback mechanism, which allows attackers to send tailored socket messages containing callback names linked to insecure global functions such as avideoConfirmHTML. These functions accept untrusted data and use innerHTML for rendering, creating an avenue for script execution in the victim's browser without authentication or user interaction.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.