---
id: CVE-2021-39183
aliases:
  - GHSA-2hfj-cxw7-g45p
  - GO-2022-0291
title: Unsafe inline XSS in pasting DOM element into chat
summary: Unsafe inline XSS in pasting DOM element into chat
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L'
vendor: owncast
product: github.com/owncast/owncast
ecosystem: go
affected:
  - github.com/owncast/owncast < 0.0.9
patched:
  - github.com/owncast/owncast 0.0.9
published: '2021-12-14'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2hfj-cxw7-g45p'
references:
  - url: 'https://github.com/owncast/owncast/security/advisories/GHSA-2hfj-cxw7-g45p'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-39183'
  - url: 'https://github.com/owncast/owncast'
tags:
  - osv
  - go
epss: 0.00747
epssPercentile: 0.5292
ingestedAt: '2026-07-09T18:56:35.437Z'
---

## Overview

### Impact

Inline scripts are executed when Javascript is parsed via a paste action.

1. Open https://watch.owncast.online/
2. Copy and then paste `<img src=null onerror=alert('hello')>` into the
chat field.
3. An alert should pop up.

### Patches
```
    ⋮ 13 │    // Content security policy
    ⋮ 14 │    csp := []string{
    ⋮ 15 │        "script-src 'self' 'sha256-2HPCfJIJHnY0NrRDPTOdC7AOSJIcQyNxzUuut3TsYRY='",
    ⋮ 16 │        "worker-src 'self' blob:", // No single quotes around blob:
    ⋮ 17 │    }
```

Will be patched in 0.0.9 by blocking `unsafe-inline` Content Security Policy and specifying the `script-src`.  The `worker-src` is required to be set to `blob` for the video player.

### For more information

If you have any questions or comments about this advisory:
* Open an issue in [owncast/owncast](https://github.com/owncast/owncast/issues)
* Email us at [gabek@real-ity.com](mailto:gabek@real-ity.com)


## Affected packages

- `github.com/owncast/owncast < 0.0.9`

## Remediation

Upgrade to a patched release:

- `github.com/owncast/owncast 0.0.9`
