Paella Player: Stored XSS via caption cue text
Published Sep 17, 2026
8.7
HIGHCVSS 3.1
EPSS 0.56%
Description
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Affected products
-
- Version < 19.7StatusaffectedConstraints-
- Version >= 20.0, < 20.2StatusaffectedConstraints-
- Version
-
- Version < 2.12.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Opencast | Opencast | n/a |
| |||||||||
| Polimediaupv | Paella-Player | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
org.opencastproject:opencast-engage-paella-player-7
Maven
Introduced 0 Fixed 19.7org.opencastproject:opencast-engage-paella-player-7
Maven
Introduced 20.0 Fixed 20.2paella-core
npm
Introduced 0 Fixed 1.50.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Maven | org.opencastproject:opencast-engage-paella-player-7 | 0 | 19.7 |
| Maven | org.opencastproject:opencast-engage-paella-player-7 | 20.0 | 20.2 |
| npm | paella-core | 0 | 1.50.6 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 22, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.56% (0.00559) | 44.52th | v5 (v2026.06.15) |
| Sep 18, 2026 | 0.39% (0.00392) | 33.20th | v5 (v2026.06.15) |
References (11)
- https://github.com/advisories/GHSA-m6c8-jcw2-5r25 Advisory
- https://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40 x_refsource_MISC
- https://github.com/opencast/opencast/pull/7736 x_refsource_MISC
- https://github.com/opencast/opencast/releases/tag/19.7 x_refsource_MISC
- https://github.com/opencast/opencast/releases/tag/20.2 x_refsource_MISC
- https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25 exploitx_refsource_CONFIRM
- https://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b x_refsource_MISC
- https://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4 x_refsource_MISC
- https://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21 x_refsource_MISC
- https://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-77615
Change history (0)
No recorded changes yet.