Loading...
Skip to main content

CVE-2026-49279

HIGH

WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)

Published June 4, 2026Updated June 4, 2026Source: osv

Summary

# AVideo: Stored XSS via `autoEvalCodeOnHTML` in MessageSQLite WebSocket Handler ## Summary AVideo has a stored XSS vulnerability in the WebSocket messaging system. The `MessageSQLite.php` handler only strips `autoEvalCodeOnHTML` from `$json['msg']`, but `msgToResourceId()` reads from `$msg['json']` with higher priority. An attacker can place the XSS payload in the `json` key instead of `msg`, bypassing the sanitization entirely. ## Affected Versions AVideo <= latest ## Vulnerability Details ### Root Cause: Shallow sanitization only covers `$json['msg']` `plugin/YPTSocket/MessageSQLite.php` lines 268-271 — the incomplete fix: ```php if (empty($msgObj->isCommandLineInterface) && ($msgObj->sentFrom ?? '') !== 'php') { if (is_array($json['msg'] ?? null)) { unset($json['msg']['autoEvalCodeOnHTML']); // Only strips from $json['msg'] } } ``` `plugin/YPTSocket/MessageSQLite.php` lines 361-367 — the bypass via `msgToResourceId()`: ```php if (!empty($msg['json'])) { $obj['msg'] = $msg['json']; // $msg['json']['autoEvalCodeOnHTML'] is NEVER stripped } else if (!empty($msg['msg'])) { $obj['msg'] = $msg['msg']; // Only this path was sanitized } else { $obj['msg'] = $msg; } ``` Compare with the correctly patched `Message.php` (lines 254-256): ```php $json = removeAutoEvalCodeOnHTMLRecursive($json); // Strips from ALL nested paths ``` And `MessageSQLiteV2.php` (lines 302-303): ```php $json = removeAutoEvalCodeOnHTMLRecursive($json); // Same recursive fix ``` `MessageSQLite.php` does not call `removeAutoEvalCodeOnHTMLRecursive()` at all. ### Attack Chain - Attacker sends a WebSocket message with `autoEvalCodeOnHTML` in the `json` key instead of `msg` - The fix at line 268-271 only checks `$json['msg']` — the `json` key is untouched - `msgToResourceId()` reads `$msg['json']` first (line 361) because `!empty($msg['json'])` is true - The payload is delivered to the victim's WebSocket client and evaluated via `autoEvalCodeOnHTML` ## Proof of Concept ```javascript // Connect to AVideo WebSocket as authenticated user const ws = new WebSocket('wss://TARGET/plugin/YPTSocket/server.php?token=USER_TOKEN'); ws.onopen = () => { ws.send(JSON.stringify({ msg: "Hello", // sanitized path — decoy json: {autoEvalCodeOnHTML: "alert('XSS')"}, // unsanitized path — payload to_users_id: VICTIM_USER_ID, resourceId: RESOURCE_ID })); }; // Victim's client evaluates alert('XSS') via autoEvalCodeOnHTML mechanism ``` ## Impact An authenticated attacker can: - Execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system - Steal session cookies and authentication tokens - Perform account takeover via session hijacking - Chain with CSRF to execute admin actions on behalf of the victim The vulnerability affects the default SQLite WebSocket backend configuration. ## Suggested Remediation Apply `removeAutoEvalCodeOnHTMLRecursive()` in `MessageSQLite.php`, consistent with `Message.php` and `MessageSQLiteV2.php`: ```php // Before (vulnerable — shallow strip): if (is_array($json['msg'] ?? null)) { unset($json['msg']['autoEvalCodeOnHTML']); } // After (fixed — recursive strip): $json = removeAutoEvalCodeOnHTMLRecursive($json); ```

Affected Packages (1)

PackageEcosystemAffectedFixed In
wwbn/avideo
packagist
10.4, 10.8, 11, 11.1 (+14 more)Range-based data available

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-79
    Cross-site Scripting (XSS)MITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 8.4 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Confidentiality
Integrity
Availability

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Frequently Asked Questions

What is CVE-2026-49279?
WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass) This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.4/10).
How do I check if my project is affected by CVE-2026-49279?
CVE-2026-49279 affects wwbn/avideo. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-49279 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
8.4

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-2fhx-q92v-5fhv

Related CVEs

  • CVE-2026-33351
    CRITICAL

    AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass

  • CVE-2026-33478
    CRITICAL

    AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection

  • CVE-2026-54458
    CRITICAL

    WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin

  • CVE-2026-33648
    HIGH

    AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path

  • CVE-2026-40909
    HIGH

    WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)

  • CVE-2026-33513
    HIGH

    AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)

  • CVE-2026-33717
    HIGH

    AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURL

  • CVE-2026-60092
    MEDIUM

    AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies