Executive brief
Coturn is an open-source server used for relaying media traffic in VoIP and web communication systems. A security flaw in its web-based administration interface allows an attacker to inject malicious scripts by using a specially crafted username during a connection request. If an administrator views the active session list, these scripts could execute in their browser, potentially allowing the attacker to perform unauthorized actions or steal administrative session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Coturn web-admin interface due to improper neutralization of the USERNAME value. The root cause involves insufficient input validation in 'is_secure_string()' (which fails to filter '<', '>', and '&') and a lack of HTML entity encoding when rendering the username in the session list ('/ps') within 'turn_admin_server.c'. An attacker can exploit this by creating a TURN allocation with a malicious payload in the username field. In deployments using '--no-auth', no credentials are required; otherwise, valid TURN credentials are needed. Successful exploitation allows execution of arbitrary JavaScript in the context of an authenticated administrator's session. The issue is fixed in version 4.11.0.
Affected products
- coturn coturn < 4.11.0
Timeline
- 2026-05-24: advisory: GitHub Security Advisory published
- 2026-05-08: patched: Version 4.11.0 released
- 2026-06-18: disclosed: CVE published to NVD