{"id":"CVE-2026-77615","summary":"Paella Player: Stored XSS via caption cue text","details":"Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.","aliases":["GHSA-m6c8-jcw2-5r25"],"modified":"2026-09-19T03:46:49.198650886Z","published":"2026-09-17T20:51:26.147Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77615.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"19.7"},{"introduced":"20.0"},{"fixed":"20.2"},{"fixed":"2.12.11"}]}],"cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/opencast/opencast/releases/tag/19.7"},{"type":"WEB","url":"https://github.com/opencast/opencast/releases/tag/20.2"},{"type":"WEB","url":"https://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77615.json"},{"type":"ADVISORY","url":"https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77615"},{"type":"FIX","url":"https://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40"},{"type":"FIX","url":"https://github.com/opencast/opencast/pull/7736"},{"type":"FIX","url":"https://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b"},{"type":"FIX","url":"https://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4"},{"type":"FIX","url":"https://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencast/opencast","events":[{"introduced":"0"},{"fixed":"701682c635f668228c3e8fb7b4564b3294788e40"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/polimediaupv/paella-core","events":[{"introduced":"0"},{"fixed":"94a36490808ac5a1f60a0745d71ec9253f6d206b"},{"fixed":"9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4"}],"database_specific":{"source":"REFERENCES"}}],"versions":["1.50.5","1.50.4","1.50.3","1.50.2","1.50.1","1.50.0","1.49.7","1.49.6","1.49.5","1.49.4","1.49.3","1.49.2","1.49.1","1.49.0","1.48.2","1.48.1","1.48.0","1.47.1","1.47.0","1.46.6","1.46.5","1.46.4","1.46.3","1.46.2","1.46.1","1.46.0","1.45.0","1.44.2","1.44.1","1.44.0","1.43.1","1.43.0","1.42.0","1.41.0","1.40.0","1.39.11","1.39.10","1.39.9","1.39.8","1.39.7","1.39.6","1.39.5","1.39.4","1.39.3","1.39.2","1.39.1","1.39.0","1.38.0","1.37.2","1.37.1","1.37.0","1.36.0","1.35.2","1.35.1","1.35.0","1.34.1","1.33.0","1.32.0","1.31.2","1.31.1","1.31.0","1.30.3","1.30.2","1.30.1","1.30.0","1.29.0","1.28.3","1.28.2","1.28.1","1.28.0","1.27.0","1.26.0","1.25.1","1.25.0","1.24.1","1.24.0","1.23.1","1.22.2","1.22.1","1.22.0","1.21.2","1.21.1","1.21.0","1.20.2","1.20.1","1.20.0","1.19.0","1.18.2","1.18.1","1.18.0","1.17.0","1.16.0","1.15.1","1.15.0","1.14.2","1.14.1","1.14.0","1.13.1","1.13.0","1.12.0","1.11.3","1.11.2","1.11.1","1.11.0","1.10.0","1.9.0","1.8.9","1.8.8","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.8.0","1.7.0","1.6.0","1.5.2","1.5.1","1.5.0","1.4.3","1.4.2","1.4.1","1.4.0","1.3.2","1.3.1","1.3.0","1.0.51","1.0.50","1.0.49","1.0.48","1.0.47","1.0.46","1.0.45","1.0.43","1.0.42","1.0.41","1.0.40","1.0.39","1.0.38","1.0.37","1.0.36","1.0.35","1.0.34","1.0.33","1.0.32","1.0.31","1.0.30","1.0.29","1.0.28","1.0.27","1.0.26","1.0.25","1.0.24","1.0.23","1.0.22","1.0.21","1.0.20","1.0.19","1.0.16","1.0.15","1.0.14","1.0.13","1.0.12","1.0.9","1.0.8","1.0.7","1.0.6","1.0.5","1.0.2","1.0.1","1.0.0","1.0.0-beta.26","1.0.0-beta.25","1.0.0-beta.24","1.0.0-beta.23","1.0.0-beta.22","1.0.0-beta.21","1.0.0-beta.20","1.0.0-beta.19","1.0.0-beta.18","1.0.0-beta.17","1.0.0-beta.16","1.0.0-beta.15","1.0.0-beta.14","1.0.0-beta.13","1.0.0-beta.12","1.0.0-beta.11","1.0.0-beta.10","1.0.0-beta.9","1.0.0-beta.8","1.0.0-beta.7","1.0.0-beta.6","1.0.0-beta.5","1.0.0-beta.4","1.0.0-beta.3","1.0.0-beta.2","1.0.0-beta.1","1.0.0-beta.0","1.0.0-alpha.29","1.0.0-alpha.28","1.0.0-alpha.27","1.0.0-alpha.26","1.0.0-alpha.25","1.0.0-alpha.24","1.0.0-alpha.23","1.0.0-alpha.22","1.0.0-alpha.21","1.0.0-alpha.20","1.0.0-alpha.19","1.0.0-alpha.18","1.0.0-alpha.17","1.0.0-alpha.16","1.0.0-alpha.15","1.0.0-alpha.14","1.0.0-alpha.13","1.0.0-alpha.12","1.0.0-alpha.11","1.0.0-alpha.10","1.0.0-alpha.9","1.0.0-alpha.8","1.0.0-alpha.7","1.0.0-alpha.6","1.0.0-alpha.5","1.0.0-alpha.4","1.0.0-alpha.3","1.0.0-alpha.2","1.0.0-alpha.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/polimediaupv/paella-player","events":[{"introduced":"0"},{"fixed":"6fe4af7306044198c8e91e2e7f4128428b83cf03"}],"database_specific":{"source":"REFERENCES"}}],"versions":["@asicupv/paella-ai-plugins@2.8.1","@asicupv/paella-zoom-plugin@2.5.3","@asicupv/paella-webgl-plugins@2.4.1","@asicupv/paella-video-plugins@2.5.2","@asicupv/paella-user-tracking@2.4.2","@asicupv/paella-slide-plugins@2.6.1","@asicupv/paella-extra-plugins@2.9.1","@asicupv/paella-basic-plugins@2.6.1","@asicupv/paella-ai-plugins@2.8.0","@asicupv/paella-extra-plugins@2.8.7","@asicupv/paella-embedapi@2.11.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}