CVE-2026-77615: Paella Player: Stored XSS via caption cue text
Paella Player is a set of libraries to create a multi stream video player. Prior to Paulla Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Paella Playerto a version that resolves this vulnerability.Fixed in 2.12.11
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using Paella Player before version 2.12.11 are affected. The advisory specifically identifies Opencast versions prior to 19.7 and 20.2 as using the vulnerable player version.
What does an attacker need to exploit this issue?
The attack is through closed-caption cue text, and the vector indicates network reachability, low attack complexity, and low privileges. A user must interact with the affected content for the XSS payload to execute.
What should be done if the deployment is vulnerable?
Upgrade Paella Player to version 2.12.11. For Opencast, update to a version that includes the corrected Paella Player dependency, identified as 19.7 or 20.2 or later.