WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but msgToResourceId() reads from $msg['json'] with higher priority. An attacker can place the XSS payload in the json key instead of msg, bypassing the sanitization entirely. An authenticated attacker can execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system, stealing session cookies and authentication tokens, taking over accounts through session hijacking, and chaining with CSRF to perform admin actions on the victim's behalf, in the default SQLite WebSocket backend configuration. This issue has a patch that has yet to be officially released, see https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23.
CVE-2026-49279
This high-severity CVE scores 7.7 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.1%, top 68% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.7
- EG Score
- 7.7(low)
- EG Risk
- —
- EPSS
- 25.0%
- KEV
- Not listed
Published
June 4, 2026
Last Modified
July 18, 2026
Advisory Details (2)
Auto-updated Jul 15, 2026Stored XSS via autoEvalCodeOnHTML in MessageSQLite WebSocket Handler · Advisory · WWBN/AVideo · GitHub
https://github.com/WWBN/AVideo/security/advisories/GHSA-2fhx-q92v-5fhvcommit 3e0b3ce2bfa7 (WWBN/AVideo)
Fix landed in WWBN/AVideo commit 3e0b3ce2bfa7 — awaiting tagged release
https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23Vendor Advisories for CVE-2026-49279(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(1)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| composer | wwbn/avideo | — | ghsa |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Packagist(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| wwbn/avideo | 10.4 ... 29.0 (18 versions) | — | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 9× in last 7d / 19× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-16 10:27 UTCGHSA enrichment
- 2026-07-15 21:24 UTCEG score recompute▲ 7.70
- 2026-07-15 21:24 UTCGHSA enrichment
- 2026-07-15 21:23 UTCMITRE cvelistV5CVSS v3 → 7.7 · CVSS v4 → 7.7
- 2026-07-14 16:25 UTCGHSA enrichment
- 2026-07-11 12:37 UTCGHSA enrichment
- 2026-07-08 09:36 UTCGHSA enrichment
- 2026-07-03 19:15 UTCGHSA enrichment
- 2026-06-30 00:51 UTCGHSA enrichment
- 2026-06-26 21:49 UTCGHSA enrichment
- 2026-06-23 18:43 UTCGHSA enrichment
- 2026-06-20 12:08 UTCGHSA enrichment
- 2026-06-17 07:32 UTCGHSA enrichment
- 2026-06-14 23:18 UTCEPSS rescore
- 2026-06-14 04:22 UTCGHSA enrichment
- 2026-06-13 23:00 UTCEPSS rescore
- 2026-06-12 23:12 UTCEPSS rescore
Show 4 moreShow fewer
- 2026-06-11 01:12 UTCGHSA enrichment
- 2026-06-07 22:10 UTCGHSA enrichment
- 2026-06-04 19:10 UTCEG score recompute
- 2026-06-04 19:10 UTCGHSA enrichment
Related CVEs(same product + same CWE)
Same product
10 showncomposer:wwbn/avideo
Frequently asked(5)
What is CVE-2026-49279?
When was CVE-2026-49279 disclosed?
Is CVE-2026-49279 actively exploited?
What is the CVSS score of CVE-2026-49279?
How do I remediate CVE-2026-49279?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-49279
Is Your Infrastructure Affected by CVE-2026-49279?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.