Medium · 4.8 Node.js & npm GHSA-m6c8-jcw2-5r25 CVE-2026-77615
Stored XSS in Paella Player Caption Rendering (CVE-2026-77615)
Paella Player, the video player library used by Opencast, contains a stored cross-site scripting vulnerability in how it renders closed caption cue text. A fix is available in the paella-core package.
AI summary
A cross-site scripting vulnerability has been identified in Paella Player, a set of libraries used to build multi-stream video players and embedded in the Opencast lecture capture platform. The issue stems from improper neutralization of closed caption cue text when it is rendered on a web page, allowing an attacker to inject script content that runs in the context of a viewer's browser session. A fixed version of the affected npm package is available.
What happened
A vulnerability tracked as CVE-2026-77615 (GHSA-m6c8-jcw2-5r25) was identified in Paella Player, a library used to create multi-stream video players and used within the Opencast platform. The flaw involves improper neutralization of input when closed caption cue text is rendered, which can lead to a cross-site scripting (XSS) condition. The advisory indicates that caption cue text processed via WebVTT/DFXP caption formats in the Paella player component is not properly sanitized before being rendered on the page.
Technical cause
The vulnerability is classified under CWE-79, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause is that caption cue text is rendered into the page without adequate sanitization, allowing an attacker who can supply or influence caption content to embed executable script. The CVSS vector (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N) indicates the attack can be carried out over the network with low complexity, requires low-privileged access and user interaction, and the impact crosses a security scope boundary (Scope: Changed) with high confidentiality and integrity impact but no impact on availability.
Why it matters
Because the vulnerability has Scope: Changed, successful exploitation can affect resources beyond the vulnerable component itself, such as the broader web application session in which the player is embedded. A stored XSS of this nature means malicious caption content could persist and execute against any user who views the affected media, potentially exposing session data or enabling further actions within the victim's authenticated context.
Who is affected
Users and operators of the paella-core npm package prior to version 1.50.6 are affected. The fact package specifically documents paella-core as the affected package; the advisory text also references this issue as impacting Opencast deployments prior to certain versions, but no specific Opencast version identifiers were supplied in the validated package, so we are not naming any Opencast version numbers here.
Affected versions
The paella-core package is affected in versions starting from 0 up to, but not including, 1.50.6. Versions prior to 1.50.6 are considered vulnerable.
Fixes and mitigation
The vulnerability is fixed in paella-core version 1.50.6. Operators using the paella-core npm package should upgrade to this fixed version to remediate the issue.
Recommended action
Site owners and developers using paella-core should update to version 1.50.6 or later as soon as practical. Review any custom integrations that render user- or externally-supplied caption content (WebVTT/DFXP) to confirm output sanitization is in place after upgrading.
PatchBriefing score
4.8 / 10 · Medium
Official CVSS: 8.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Why this score
This issue carries a CVSS base score of 8.7, driving a Patchwire score of 4.8. The score reflects a network-exploitable, low-complexity vulnerability with a scope change and high confidentiality and integrity impact, tempered by the fact that it requires low-privileged access and user interaction. There is no evidence of known exploitation or public exploit code, and no EPSS-driven urgency is indicated. A fix is available, which further supports prompt remediation over emergency response.
Affected versions
- paella-core < 1.50.6
- vulnerable
- ≥ 1.50.6
- patched
Reported fixes
The vulnerability is fixed in paella-core version 1.50.6. Operators using the paella-core npm package should upgrade to this fixed version to remediate the issue.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email