logo

CVE-2026-55879: Critical XSS Vulnerability in OpenReplay Leads to Account Takeover

ID: 630f5d6b-d977-5514-9134-395d975f51a9

STIX ID: report--630f5d6b-d977-5514-9134-395d975f51a9

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-11

Date Updated: 2026-07-17

...
...

CVE-2026-55879 is a critical stored XSS in OpenReplay dashboards (affecting v1.24.0–1.25.0) that allows unauthenticated attackers to inject scripts that can read session JWTs from localStorage and enable account takeover; the issue has CVSS 9.3, was published on 2026-07-10, and is fixed in OpenReplay 1.25.0 — users should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.