GHSA-m6c8-jcw2-5r25
HIGHCVE-2026-77615The Opencast Paella player renders caption cue text into innerHTML without escaping. The captions canvas clears captionsContainer.innerHTML and then appends each active cue with captionsContainer.innerHTML += cue, so HTML inside a WebVTT or DFXP cue becomes live DOM and executes in the Opencast origin.
- Affected
- < 19.7
- Fixed in
- 19.7
- Weakness
- CWE-79
- Published
- 2026-09-18
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference