CVE-2026-89256
AVideo’s Bookmark plugin contains a stored cross‑site scripting flaw that lets a video owner inject malicious JavaScript into bookmark names. Anyone who watches the affected video will execute that script in their browser. The vulnerability is critical because it can be used to steal user data or hijack accounts.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the AVideo platform who have the Bookmark plugin enabled and who allow video owners to set bookmark names. The flaw affects all versions of AVideo that include the plugin before a patch is released.
Real-world impact
An attacker can run arbitrary JavaScript in the browser of anyone who watches the affected video, potentially stealing cookies, session data, or performing actions on behalf of the user.
Why this severity
The CVSS score of 9.3 reflects the high impact of the vulnerability: it is exploitable over the network, requires low effort, and can lead to complete compromise of the victim’s browser session.
What to do about it
- ›Disable or remove the Bookmark plugin until a vendor patch is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources