{"id":"CVE-2026-55491","summary":"BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name","details":"BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script content, and the script executed in another user's browser when that user replayed the recording. This issue is fixed in version 3.0.29.","aliases":["GHSA-57p5-c888-74f9"],"modified":"2026-08-24T03:59:08.961553Z","published":"2026-08-20T21:35:42.546Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55491.json"},"references":[{"type":"WEB","url":"https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.29"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55491.json"},{"type":"ADVISORY","url":"https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-57p5-c888-74f9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55491"},{"type":"FIX","url":"https://github.com/bigbluebutton/bigbluebutton/commit/a53f2b92022388bfa4109d3136d1f3a932404b1b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bigbluebutton/bigbluebutton","events":[{"introduced":"0"},{"fixed":"a53f2b92022388bfa4109d3136d1f3a932404b1b"},{"fixed":"e9d0534de2f014d1903d8c54885ca6acd5758a69"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.0.29"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v3.0.28","v3.0.27","v3.0.26","v3.0.25","v3.0.24","v3.0.23","v3.0.22","v3.0.21","v3.0.20","v3.0.19","v3.0.18","v3.0.17","v3.0.16","v3.0.15","v3.0.14","v3.0.13","v3.0.12","v3.0.11","v3.0.8","v3.0.10","v3.0.9","v3.0.7","v3.0.5","v3.0.4","v3.0.2","v3.0.3","v3.0.0","v3.0.1","v3.0.0-rc.4","v3.0.0-rc.3","v3.0.0-rc.2","v3.0.0-rc.1","3.0.0-rc.1","v3.0.0-beta.7","v3.0.0-beta.6","v3.0.0-beta.5","v3.0.0-beta.4","v3.0.0-beta.3","v3.0.0-beta.2","v3.0.0-beta.1","v3.0.0-alpha.7","v3.0.0-alpha.6","v3.0.0-alpha.4","v3.0.0-alpha.3","v3.0.0-alpha.2","v3.0.0-alpha.1","v2.4-beta-4","v2.4-beta-3","v2.4-beta-2","v2.4-beta-1","v2.4-alpha-1","v2.3.1","v2.3.0","v2.3-rc-2","v2.3-rc-1","v2.3-beta-5","v2.3-beta-4","v2.3-beta-3","v2.3-beta-2","v2.3-beta-1","v2.3-alpha-8","v2.3-alpha-7","v2.3-alpha-6","v2.3-alpha-5","v2.3-alpha-4","v2.3-alpha-3","v2.3-alpha-2","v2.3-alpha-1","2.2-rc-3","2.2-rc-2","2.2-rc-1","2.2-beta-23","2.2-beta-22","2.2-beta-21","2.2-beta-20","2.2-beta-19","2.2-beta-18","2.2-beta-17","2.2-beta-16","2.2-beta-15","2.2-beta-14","2.2-beta-12","2.2-beta-11","2.2-beta-10","2.2-beta-9","2.2-beta-8","2.2-beta-7","2.2-beta-6","2.2-beta-5","2.2-beta-4","2.2-beta-3","2.2-beta-2","dcs-2-a","v0.9.0-beta","v0.8","v0.8rc2","v0.8b4.0","v0.8b4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55491.json","vanir_signatures_modified":"2026-08-24T03:59:08Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/bigbluebutton/bigbluebutton/commit/e9d0534de2f014d1903d8c54885ca6acd5758a69","target":{"file":"bbb-common-web/src/main/java/org/bigbluebutton/api/model/validator/ContentTypeValidator.java"},"deprecated":false,"digest":{"line_hashes":["171893269864785211469490273169048262713","47513062551889159024279848957257221677","47534136755514569330082593582056901645","305711170735977579354243743203764300734"],"threshold":0.9},"id":"CVE-2026-55491-50314cb5"},{"source":"https://github.com/bigbluebutton/bigbluebutton/commit/e9d0534de2f014d1903d8c54885ca6acd5758a69","target":{"file":"bbb-common-web/src/main/java/org/bigbluebutton/api/model/request/GuestWait.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["242161247612091681100423810891252332199","336526248208291997279047623853597944547","176670872078812572766531800661639465980","59848718246103412995454615425602721599","300146863375822521627161709113960709769","86182153846938859175093782766426681134","587832367915583864481176421532364858"]},"id":"CVE-2026-55491-6b266d02","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/bigbluebutton/bigbluebutton/commit/e9d0534de2f014d1903d8c54885ca6acd5758a69","target":{"file":"bbb-common-web/src/main/java/org/bigbluebutton/api/model/request/JoinMeeting.java"},"deprecated":false,"digest":{"line_hashes":["88434799640558778257288228062920158108","7251528062029604322044188788066397728","44645748650457402782589726500135861904","192557370480273023032816370500131288245","161592334185906639935064986523263119018","62985558293612551570530917162184907836","121902534756978404699464605633463101852"],"threshold":0.9},"id":"CVE-2026-55491-a7aeaaed","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["271139484060790763689471598057212025245","318692501593149580994691245162046212209","152607542981530139437516851601796342454","91766718737915328782003972435491559125","276801988874348428298731527743172764529","1523102452266288933963449728119574323","128192166450262049977948850596230053321","163633938008796078489867408267787334498","31749120539060753812456029450628446990","121902534756978404699464605633463101852"],"threshold":0.9},"id":"CVE-2026-55491-de39e59c","signature_type":"Line","signature_version":"v1","source":"https://github.com/bigbluebutton/bigbluebutton/commit/e9d0534de2f014d1903d8c54885ca6acd5758a69","target":{"file":"bbb-common-web/src/main/java/org/bigbluebutton/api/model/request/SendChatMessage.java"}},{"target":{"file":"bbb-common-web/src/main/java/org/bigbluebutton/api/model/validator/ContentTypeValidator.java","function":"isValid"},"deprecated":false,"digest":{"function_hash":"234938860166603979418016340001434754519","length":648},"id":"CVE-2026-55491-e6a7f401","signature_type":"Function","signature_version":"v1","source":"https://github.com/bigbluebutton/bigbluebutton/commit/e9d0534de2f014d1903d8c54885ca6acd5758a69"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}