eXtreme Hosting Logo
  • Home
  • Webmail
  • Integrations
  • Pricing
  • Contact
Customer portal

CVE-2026-33500

Publication date

2026-03-23 16:24:52

Family

GitHub_M

State

PUBLISHED

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `` and `` tags in comments, but explicitly disables Parsedowns `safeMode`. This creates a bypass: markdown link syntax `[text](javascript:alert(1))` is processed by Parsedowns `inlineLink()` method, which does not go through the custom `sanitizeATag()` sanitization (that only handles raw HTML tags). With `safeMode` disabled, Parsedowns built-in `javascript:` URI filtering (`sanitiseElement()`/`filterUnsafeUrlInAttribute()`) is also inactive. An attacker can inject stored XSS via comment markdown links. Commit 3ae02fa240939dbefc5949d64f05790fd25d728d contains a patch.


Copyright © 2026 eXtreme Hosting

Privacy Policy GDPR/AVG | Algemene voorwaarden