Advisory · CVE-2026-105086
AVideo video titles carry stored XSS past its sanitizer
AVideo's safeString() strips tags before decoding entities and runs twice, so doubly-encoded entities in video titles survive sanitization and execute as stored XSS on trending, gallery, embed, and playlist pages.
- Vendor
- WWBN
- Product
- AVideo
- Identifier / CWE
- CVE-2026-105086
CWE-79 - Action timing
- Immediate
Explain it like I’m five
AVideo checks video titles for bad code, then unscrambles them, but it checks before the unscrambling, and it does the whole thing twice. An attacker writes a title that looks harmless at check time but turns into live code after the unscrambling, and everyone who views the video page runs it.
- 01Malicious title uploaded
An authenticated uploader submits a video title containing doubly-encoded HTML entities.
- 02Sanitizer bypassed
safeString() strips tags before decoding entities and runs twice via setTitle() and save(), so the markup survives and is stored.
- 03Title rendered elsewhere
The stored title is rendered unescaped on trending, gallery, embed, and playlist pages.
- 04Script executes
Visitors' browsers execute the attacker's JavaScript, enabling session theft or admin actions.
What happened
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability: authenticated uploaders can inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages. It is rated critical at CVSS 9.3 under CVSS v4.0 (8.7 under v3.1) and tracked as CWE-79.
What to do
- Upgrade AVideo past 29.2.0 to a release containing the vendor fix (per the vendor security advisory GHSA-q62w-927x-vhhf).
- Review recently uploaded videos for titles containing encoded entities or markup, and remove suspicious uploads.
- Check web and application logs for uploads with unusual title content from accounts that should not have upload permission.
- Force session resets for administrators and moderators if exploitation cannot be ruled out.
Management note
Stored XSS on a video platform turns every viewer into a potential victim and every uploader account into a launch pad. The sanitizer-bypass shape here means titles that passed review yesterday may still be live payloads today. Upgrade, then audit the content library rather than assuming the fix cleans up what is already stored.