Executive brief
BigBlueButton is an open-source web conferencing platform used for virtual classrooms and meetings. The application failed to properly escape user-controlled meeting names when displaying screenshare recordings, allowing an attacker to inject malicious scripts that execute in other users' browsers when they view the recording. This could lead to account compromise, session hijacking, or data theft.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the screenshare playback template (record-and-playback/screenshare/playback/index.html.erb). The meetingName parameter was not properly HTML-escaped before being rendered in the playback page. A low-privileged user could create a meeting with a malicious script embedded in the meeting name; when another user later replayed the recording, the script would execute in their browser with their privileges. The fix involved escaping meetingName using CGI.escapeHTML in the ERB template. The vulnerability is present in all versions prior to 3.0.29 and is fixed in 3.0.29.
Affected products
- BigBlueButton BigBlueButton prior to 3.0.29
Timeline
- 2026-06-12: disclosed
- 2026-06-12: patched: Fixed in version 3.0.29
- 2026-08-20: advisory