


Perceptive Security
SOC/SIEM Consultancy

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies t…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 22:04:46
Source:
nvd.nist.gov
Web Technologies
WWBN AVideo versions 29.0 and prior contain a critical vulnerability in the YPTSocket plugin's WebSocket server. The server relays attacker-supplied JSON messages without sanitization, allowing injection into eval() functions on the client side. Unauthenticated attackers can broadcast arbitrary JavaScript code that executes in all connected users' browsers, including administrators. This leads to universal account takeover, session theft, and privileged action execution. The vulnerability affects the msg and callback fields which are processed by eval() sinks in the client-side script.
Technical details
Mitigation steps:
Affected products:
WWBN AVideo
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40911
https://github.com/WWBN/AVideo/commit/c08694bf6264eb4decceb78c711baee2609b4efd
https://github.com/WWBN/AVideo/security/advisories/GHSA-gph2-j4c9-vhhr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
