CVE-2025-62613

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-62613
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62613.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62613
Aliases
  • GHSA-mp9c-cpch-x73c
Published
2025-10-22T20:52:57Z
Modified
2025-10-24T04:21:51.930501Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
VDO.Ninja Reflected XSS Vulnerability in control.html
Details

VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to before 28.4, a reflected Cross-Site Scripting (XSS) vulnerability exists on examples/control.html through the room parameter, which is improperly sanitized before being rendered in the DOM. The application fails to validate and encode user input, allowing malicious scripts to be injected and executed. This issue has been patched in version 28.4.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/steveseguin/vdo.ninja

Affected ranges

Type
GIT
Repo
https://github.com/steveseguin/vdo.ninja
Events

Affected versions

v28.*

v28.0