CVE-2026-86188
Last modified
CVE-2026-86188 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WWBN | AVideo | <= 29.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86188?
How severe is CVE-2026-86188?
How do I fix CVE-2026-86188?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86182A vulnerability was determined in diem-project diem up to 5.…4.3
- CVE-2026-86183A vulnerability was identified in diem-project diem up to 5.…5.3
- CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypas…9.8
- CVE-2026-86185Bilibili Desktop through 1.18.0 disables TLS certificate ver…8
- CVE-2026-86186AVideo API fails to enforce rate limits when clients send a …6.5
- CVE-2026-86187WWBN AVideo generates passwords for external-login accounts …5.9
- CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notif…9.8
- CVE-2026-8619An unauthenticated denial-of-service vulnerability was ident…7.5
- CVE-2026-86190WWBN AVideo contains a broken access control vulnerability i…9.1
- CVE-2026-86191SiYuan versions before v3.8.2 contain an information disclos…4.3
- CVE-2026-86192SiYuan versions before v3.8.2 fail to properly filter privat…6.5
- CVE-2026-86193grav-plugin-api before 1.0.20 fails to validate group-inheri…8.7
Are you affected by CVE-2026-86188?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
