CVE-2026-77615

Source
https://cve.org/CVERecord?id=CVE-2026-77615
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77615
Aliases
Published
2026-09-17T20:51:26Z
Modified
2026-09-19T03:46:49Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Paella Player: Stored XSS via caption cue text
Details

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77615.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "19.7"
                },
                {
                    "introduced": "20.0"
                },
                {
                    "fixed": "20.2"
                },
                {
                    "fixed": "2.12.11"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git
github.com/opencast/opencast

Affected ranges

Type
GIT
Repo
https://github.com/opencast/opencast
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"
github.com/polimediaupv/paella-core

Affected ranges

Type
GIT
Repo
https://github.com/polimediaupv/paella-core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.0.0
1.0.0-alpha.1
1.0.0-alpha.10
1.0.0-alpha.11
1.0.0-alpha.12
1.0.0-alpha.13
1.0.0-alpha.14
1.0.0-alpha.15
1.0.0-alpha.16
1.0.0-alpha.17
1.0.0-alpha.18
1.0.0-alpha.19
1.0.0-alpha.2
1.0.0-alpha.20
1.0.0-alpha.21
1.0.0-alpha.22
1.0.0-alpha.23
1.0.0-alpha.24
1.0.0-alpha.25
1.0.0-alpha.26
1.0.0-alpha.27
1.0.0-alpha.28
1.0.0-alpha.29
1.0.0-alpha.3
1.0.0-alpha.4
1.0.0-alpha.5
1.0.0-alpha.6
1.0.0-alpha.7
1.0.0-alpha.8
1.0.0-alpha.9
1.0.0-beta.0
1.0.0-beta.1
1.0.0-beta.10
1.0.0-beta.11
1.0.0-beta.12
1.0.0-beta.13
1.0.0-beta.14
1.0.0-beta.15
1.0.0-beta.16
1.0.0-beta.17
1.0.0-beta.18
1.0.0-beta.19
1.0.0-beta.2
1.0.0-beta.20
1.0.0-beta.21
1.0.0-beta.22
1.0.0-beta.23
1.0.0-beta.24
1.0.0-beta.25
1.0.0-beta.26
1.0.0-beta.3
1.0.0-beta.4
1.0.0-beta.5
1.0.0-beta.6
1.0.0-beta.7
1.0.0-beta.8
1.0.0-beta.9
1.0.1
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.19
1.0.2
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38
1.0.39
1.0.40
1.0.41
1.0.42
1.0.43
1.0.45
1.0.46
1.0.47
1.0.48
1.0.49
1.0.5
1.0.50
1.0.51
1.0.6
1.0.7
1.0.8
1.0.9
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.13.0
1.13.1
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.2
1.19.0
1.20.0
1.20.1
1.20.2
1.21.0
1.21.1
1.21.2
1.22.0
1.22.1
1.22.2
1.23.1
1.24.0
1.24.1
1.25.0
1.25.1
1.26.0
1.27.0
1.28.0
1.28.1
1.28.2
1.28.3
1.29.0
1.3.0
1.3.1
1.3.2
1.30.0
1.30.1
1.30.2
1.30.3
1.31.0
1.31.1
1.31.2
1.32.0
1.33.0
1.34.1
1.35.0
1.35.1
1.35.2
1.36.0
1.37.0
1.37.1
1.37.2
1.38.0
1.39.0
1.39.1
1.39.10
1.39.11
1.39.2
1.39.3
1.39.4
1.39.5
1.39.6
1.39.7
1.39.8
1.39.9
1.4.0
1.4.1
1.4.2
1.4.3
1.40.0
1.41.0
1.42.0
1.43.0
1.43.1
1.44.0
1.44.1
1.44.2
1.45.0
1.46.0
1.46.1
1.46.2
1.46.3
1.46.4
1.46.5
1.46.6
1.47.0
1.47.1
1.48.0
1.48.1
1.48.2
1.49.0
1.49.1
1.49.2
1.49.3
1.49.4
1.49.5
1.49.6
1.49.7
1.5.0
1.5.1
1.5.2
1.50.0
1.50.1
1.50.2
1.50.3
1.50.4
1.50.5
1.6.0
1.7.0
1.8.0
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"
github.com/polimediaupv/paella-player

Affected ranges

Type
GIT
Repo
https://github.com/polimediaupv/paella-player
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

@asicupv/paella-ai-plugins@2.*
@asicupv/paella-ai-plugins@2.8.0
@asicupv/paella-ai-plugins@2.8.1
@asicupv/paella-basic-plugins@2.*
@asicupv/paella-basic-plugins@2.6.1
@asicupv/paella-embedapi@2.*
@asicupv/paella-embedapi@2.11.1
@asicupv/paella-extra-plugins@2.*
@asicupv/paella-extra-plugins@2.8.7
@asicupv/paella-extra-plugins@2.9.1
@asicupv/paella-slide-plugins@2.*
@asicupv/paella-slide-plugins@2.6.1
@asicupv/paella-user-tracking@2.*
@asicupv/paella-user-tracking@2.4.2
@asicupv/paella-video-plugins@2.*
@asicupv/paella-video-plugins@2.5.2
@asicupv/paella-webgl-plugins@2.*
@asicupv/paella-webgl-plugins@2.4.1
@asicupv/paella-zoom-plugin@2.*
@asicupv/paella-zoom-plugin@2.5.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77615.json"