Description
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Paella Player is a set of libraries that build a multi‑stream video player. Until version 2.12.11 the library does not sanitize closed‑caption cue text, allowing an attacker to store malicious JavaScript in that text. When a user views a video with such captions, the script is rendered in the browser, enabling arbitrary code execution in the user’s browser context. This stored XSS flaw corresponds to CWE‑79 and is fixed in version 2.12.11.

Affected Systems

The vulnerability is present in the Paella Player library versions lower than 2.12.11, which are used in Opencast prior to version 19.7 and prior to 20.2. Therefore any installation of Opencast 19.6 or earlier, 20.1 or earlier, or any system that directly incorporates a Paella Player version older than 2.12.11 is affected. The marked releases (19.7 and 20.2) include the fix.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact. The EPSS score of < 1 % suggests that, as of the latest data, the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely web‑based: an attacker who can insert or modify caption cue text will cause the malicious script to be stored and executed for any viewer of that video. With the available information, the critical risk is confined to victims who view the compromised captions, but any successful exploitation can compromise both confidentiality and integrity of the user session.

Generated by OpenCVE AI on September 19, 2026 at 19:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Paella Player library to version 2.12.11 or later
  • Upgrade Opencast to the latest release (19.7 or later, 20.2 or later) that includes the patched player
  • If an immediate upgrade is not possible, sanitize or escape all caption cue text before storing it, or disable the use of closed captions until a fix can be applied

Generated by OpenCVE AI on September 19, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m6c8-jcw2-5r25 Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Opencast
Opencast opencast
Polimediaupv
Polimediaupv paella-player
Vendors & Products Opencast
Opencast opencast
Polimediaupv
Polimediaupv paella-player

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11. Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Title Paella Player: Stored XSS via caption cue text
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Opencast Opencast
Polimediaupv Paella-player
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:50:02.242Z

Reserved: 2026-08-20T20:52:01.926Z

Link: CVE-2026-77615

cve-icon Vulnrichment

Updated: 2026-09-22T01:48:51.818Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:38.557

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-77615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')