logo

No Patch Available: The CVSS 10 Flaw Turning AVideo into an Attacker’s Playground

ID: 2e5e78d0-0f90-573c-8d25-97cb68a2937b

STIX ID: report--2e5e78d0-0f90-573c-8d25-97cb68a2937b

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVSS 10 vulnerability in AVideo's YPTSocket plugin allows unauthenticated attackers to broadcast JSON messages that are executed via client-side eval() sinks, enabling mass account takeover, remote code execution, site compromise, and persistent malicious payloads; the issue affects versions 29.0 and below with no patch available, and administrators are advised to remove eval() usage, whitelist message fields, and restrict broadcast privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.