Security Advisory

CVE-2026-39367

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-07 19:22:07
Last updated 2026-04-08 17:47:40
Assigner GitHub_M
State PUBLISHED

Description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideos EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a videos epg_link to a malicious XML file whose <title> elements contain JavaScript. This payload executes in the browser of any unauthenticated visitor to the public EPG page, enabling session hijacking and account takeover.