<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T03:58:55.145678+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373345</id>
    <title>EUVD-2026-373345</title>
    <updated>2026-10-07T03:58:55.203966+00:00</updated>
    <content>EUVD-2026-373345</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77615</id>
    <title>fkie_cve-2026-77615</title>
    <updated>2026-10-07T03:58:55.204004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-77615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m6c8-jcw2-5r25</id>
    <title>GHSA-m6c8-jcw2-5r25 — Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text</title>
    <updated>2026-10-07T03:58:55.204035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.opencastproject:opencast-engage-paella-player-7, npm: paella-core</p>
<p>## Summary</p>
<p>The Opencast Paella player renders caption cue text into `innerHTML` without escaping. The captions canvas clears `_captionsContainer.innerHTML` and then appends each active cue with `_captionsContainer.innerHTML += cue`, so HTML inside a WebVTT or DFXP cue becomes live DOM and executes in the Opencast origin.</p>
<p>The caption track is read from any media package element with a `captions/*` flavor and is served, with the player manifest, to anonymous viewers through `/search/episode.json`. The caption plugins that consume it are enabled in the default player configuration, the "Subtitles" upload that produces a `captions/source` track is active by default, and no caption processing step escapes the cue text.</p>
<p>A user who can upload a subtitle to an event and publish it stores the payload in the published caption file. Any viewer who opens the event and turns captions on runs the script.</p>
<p>Result: a non-admin content author stores JavaScript in a subtitle cue that executes in the browser session of every viewer who enables captions on that event, including anonymous viewers and authenticated staff.</p>
<p>## Affected</p>
<p>opencast/opencast, `engage-paella-player` module. Supported release lines 19.x and 20.x are affected (and 18.x). Live-confirmed on 18.8 (Paella 7, paella-core 1.50.2) and 20.0 (Paella 8, paella-core 1.50.4); 19.5 ships the code-identical caption path (paella-core 1.50.4, same `EpisodeConversor` and default plugin config as 20.0). The captions canvas uses the sam…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m6c8-jcw2-5r25"/>
  </entry>
</feed>
