PT-2026-95108 · Opencast+1 · Opencast+1

·

CVE-2026-77615

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Paella Player versions prior to 2.12.11 Opencast versions prior to 19.7 Opencast versions prior to 20.2
Description An issue exists where the player renders caption cue text into innerHTML without proper escaping. This allows a user with content authoring permissions to upload a subtitle file (such as WebVTT or DFXP) containing malicious HTML or JavaScript. When a viewer enables captions for the affected event, the script executes within the Opencast origin in the viewer's browser session. This affects anonymous viewers as well as authenticated staff, potentially leading to session theft, CSRF-token theft, and unauthorized actions against the Opencast REST API.
The issue is triggered when the player processes caption tracks served via the /search/episode.json endpoint. The vulnerable behavior occurs because the caption plugins, enabled by default, append the cue text directly to the captionsContainer.innerHTML sink without sanitization.
Recommendations Update Paella Player to version 2.12.11 or later. Update Opencast to version 19.7 or later. Update Opencast to version 20.2 or later. As a temporary mitigation, disable the WebVTT and DFXP caption plugins in the player configuration.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77615
GHSA-M6C8-JCW2-5R25

Affected Products

Opencast
Paella-Player