CVE-2026-77615 PUBLISHED

Paella Player: Stored XSS via caption cue text

Assigner: GitHub_M
Reserved: 20.08.2026 Published: 17.09.2026 Updated: 17.09.2026

Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8.7

Product Status

Vendor opencast
Product opencast
Versions
  • Version < 19.7 is affected
  • Version >= 20.0, < 20.2 is affected
Vendor polimediaupv
Product paella-player
Versions
  • Version < 2.12.11 is affected

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE