{"id":"CVE-2026-77615","title":"Paella Player is a set of libraries to create a multi stream video player","summary":"Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"opencast","product":"opencast","affected":["opencast < 19.7","opencast >= 20.0, < 20.2","paella-player < 2.12.11"],"patched":["org.opencastproject:opencast-engage-paella-player-7 19.7","org.opencastproject:opencast-engage-paella-player-7 20.2","paella-core 1.50.6"],"published":"2026-09-17","updated":"2026-09-22","sourceUpdated":"2026-09-22T02:16:32.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77615","references":[{"url":"https://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40","label":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/pull/7736","label":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/releases/tag/19.7","label":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/releases/tag/20.2","label":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25","label":"security-advisories@github.com"},{"url":"https://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b","label":"security-advisories@github.com"},{"url":"https://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4","label":"security-advisories@github.com"},{"url":"https://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21","label":"security-advisories@github.com"},{"url":"https://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03","label":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77615"},{"url":"https://github.com/advisories/GHSA-m6c8-jcw2-5r25"}],"tags":["nvd","cve.org","exploit-available","ghsa","maven"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T01:48:31.414907Z"},"epss":0.00392,"epssPercentile":0.33138,"aliases":["GHSA-m6c8-jcw2-5r25"],"ecosystem":"maven","ingestedAt":"2026-09-17T21:29:16.985Z","slug":"CVE-2026-77615","body":"## Overview\n\nPaella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-77615)\n\nAffected packages:\n\n- `org.opencastproject:opencast-engage-paella-player-7 < 19.7`\n- `org.opencastproject:opencast-engage-paella-player-7 >= 20.0, < 20.2`\n- `paella-core < 1.50.6`\n\nPatched in:\n\n- `org.opencastproject:opencast-engage-paella-player-7 19.7`\n- `org.opencastproject:opencast-engage-paella-player-7 20.2`\n- `paella-core 1.50.6`\n\nSource: https://github.com/advisories/GHSA-m6c8-jcw2-5r25","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":208847,"id":"CVE-2026-77615","ts":1790042226446,"field":"exploit_available","old":"false","new":"true"}]}