CVE-2026-89239: WWBN AVideo Reflected XSS via Referer Header Comment Breakout

Published Sep 11, 2026
·
Updated

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers can craft a Referer header containing / to close the comment and inject arbitrary JavaScript that executes in the site origin for visitors arriving from the attacker-controlled page.

Affected Software

1 affected component
AVideo>undefined

Event History

Sep 11, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

AVideo instances containing commit c3edcc274c389816d434acadac07ee78eaf330c1 are exposed when a visitor reaches the site with an attacker-controlled Referer header. The attacker does not need prior privileges, but victim interaction is required.

2

What does exploitation require?

An attacker must cause a victim to arrive from an attacker-controlled page or otherwise send a crafted Referer header. The Referer value must include */ to terminate the JavaScript comment, allowing injected JavaScript to execute in the AVideo site origin.

3

What is the potential impact if exploitation succeeds?

Injected script executes with the affected AVideo site's origin in the victim's browser. The available data rates confidentiality and integrity impact as low and does not identify an availability impact.

4

How can I determine whether an instance is affected?

Check whether the deployed AVideo code includes commit c3edcc274c389816d434acadac07ee78eaf330c1 and whether showAlertMessage() places the Referer header into a JavaScript comment without encoding. The provided data does not identify affected release versions or a fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203