Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77615.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "19.7"
},
{
"introduced": "20.0"
},
{
"fixed": "20.2"
},
{
"fixed": "2.12.11"
}
],
"source": "AFFECTED_FIELD"
}
]
}