CVE-2026-89255: AVideo LoginControl Stored XSS via PGP Public Key

Published Sep 11, 2026
·
Updated

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.

Affected Software

1 affected component
AVideo LoginControl plugin>=undefined

Event History

Sep 11, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this vulnerability?

AVideo deployments using the LoginControl plugin are exposed if administrators view the profile tab of a user who has submitted a crafted PGP public key. The attacker must have an authenticated account capable of submitting that key.

2

What does an attacker need to exploit it?

The attacker needs low-privileged authenticated access and must convince or wait for an administrator to view the attacker-controlled user's profile tab. Exploitation relies on submitting a PGP public key containing malicious JavaScript.

3

Are administrators directly affected?

The injected script executes in the administrator's browser session when the administrator views the affected user's profile tab. This can expose the administrator's session and allow actions with that session's privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203