CVE-2026-49279: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WWBN AVideo
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but msgToResourceId() reads from $msg['json'] with higher priority. An attacker can place the XSS payload in the json key instead of msg, bypassing the sanitization entirely. An authenticated attacker can execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system, stealing session cookies and authentication tokens, taking over accounts through session hijacking, and chaining with CSRF to perform admin actions on the victim's behalf, in the default SQLite WebSocket backend configuration. This issue has a patch that has yet to be officially released, see https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23.
AI Analysis
Technical Summary
WWBN AVideo, an open source video platform, has a stored XSS vulnerability (CWE-79) in versions 29.0 and below. The vulnerability is in the MessageSQLite WebSocket Handler where the autoEvalCodeOnHTML parameter is sanitized only when present in $json['msg'], but the function msgToResourceId() prioritizes $msg['json'], allowing an attacker to bypass sanitization by placing the payload in the json key. This flaw enables an authenticated attacker to execute arbitrary JavaScript in any connected user's browser session, facilitating session hijacking and unauthorized actions via CSRF chaining. The vulnerability affects the default SQLite WebSocket backend configuration. A patch has been committed but is not yet officially released.
Potential Impact
An authenticated attacker can execute arbitrary JavaScript in other users' browsers connected via the WebSocket messaging system. This can lead to theft of session cookies and authentication tokens, enabling account takeover. Additionally, attackers can perform administrative actions on behalf of victims by chaining this with CSRF attacks. The vulnerability compromises confidentiality, integrity, and availability of user accounts and potentially the application.
Mitigation Recommendations
A patch addressing this vulnerability has been committed but is not yet officially released. Users should monitor the official WWBN AVideo repository and apply the official fix once available. Until then, consider restricting WebSocket access to trusted users and environments to reduce risk. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-49279: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WWBN AVideo
Description
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but msgToResourceId() reads from $msg['json'] with higher priority. An attacker can place the XSS payload in the json key instead of msg, bypassing the sanitization entirely. An authenticated attacker can execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system, stealing session cookies and authentication tokens, taking over accounts through session hijacking, and chaining with CSRF to perform admin actions on the victim's behalf, in the default SQLite WebSocket backend configuration. This issue has a patch that has yet to be officially released, see https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23.
CVSS v4.0
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WWBN AVideo, an open source video platform, has a stored XSS vulnerability (CWE-79) in versions 29.0 and below. The vulnerability is in the MessageSQLite WebSocket Handler where the autoEvalCodeOnHTML parameter is sanitized only when present in $json['msg'], but the function msgToResourceId() prioritizes $msg['json'], allowing an attacker to bypass sanitization by placing the payload in the json key. This flaw enables an authenticated attacker to execute arbitrary JavaScript in any connected user's browser session, facilitating session hijacking and unauthorized actions via CSRF chaining. The vulnerability affects the default SQLite WebSocket backend configuration. A patch has been committed but is not yet officially released.
Potential Impact
An authenticated attacker can execute arbitrary JavaScript in other users' browsers connected via the WebSocket messaging system. This can lead to theft of session cookies and authentication tokens, enabling account takeover. Additionally, attackers can perform administrative actions on behalf of victims by chaining this with CSRF attacks. The vulnerability compromises confidentiality, integrity, and availability of user accounts and potentially the application.
Mitigation Recommendations
A patch addressing this vulnerability has been committed but is not yet officially released. Users should monitor the official WWBN AVideo repository and apply the official fix once available. Until then, consider restricting WebSocket access to trusted users and environments to reduce risk. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-28T20:07:58.861Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a57fcc868715ace4384e4a8
Added to database: 07/15/2026, 21:34:00 UTC
Last enriched: 07/23/2026, 22:39:06 UTC
Last updated: 08/28/2026, 22:52:11 UTC
Views: 94
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.