Executive brief
AVideo is a video hosting and streaming platform, and the Bookmark plugin allows video owners to create named chapter bookmarks. A video owner can inject malicious scripts via bookmark names that are not properly encoded, causing every visitor to that video to execute the attacker's JavaScript in the AVideo origin. This enables account compromise, credential theft, and malware distribution to all video viewers.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the AVideo Bookmark plugin (CWE-79). The vulnerability exists in the bookmark-saving endpoint (plugin/Bookmark/page/bookmarkSave.json.php), which accepts a chapter name via the `name` parameter and stores it without any HTML encoding. When the video watch page renders, the stored bookmark names are concatenated directly into HTML via generateChaptersHTML() without escaping, allowing any visitor to execute injected JavaScript. Attack requires the attacker to be a video owner (PR:L) and for the victim to visit the affected video page (UI:R), but scope changes to cross-origin (S:C) since the script runs in the AVideo origin. The vulnerability affects all AVideo versions up to commit c3edcc274c389816d434acadac07ee78eaf330c1 and was unfixed at time of disclosure.
Affected products
- WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1
Timeline
- 2026-09-11: disclosed: Vulnerability published and CVE-2026-89256 assigned
- 2026-08-27: advisory: GitHub Security Advisory GHSA-jggq-mm5m-r5wv published by DanielnetoDotCom