---
id: CVE-2026-77615
title: Paella Player is a set of libraries to create a multi stream video player
summary: >-
  Paella Player is a set of libraries to create a multi stream video player.
  Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2),
  there is a potential XSS attack though closed captions cue text. This
  vulnerability i…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: opencast
product: opencast
affected:
  - opencast < 19.7
  - 'opencast >= 20.0, < 20.2'
  - paella-player < 2.12.11
patched:
  - 'org.opencastproject:opencast-engage-paella-player-7 19.7'
  - 'org.opencastproject:opencast-engage-paella-player-7 20.2'
  - paella-core 1.50.6
published: '2026-09-17'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77615'
references:
  - url: >-
      https://github.com/opencast/opencast/commit/701682c635f668228c3e8fb7b4564b3294788e40
    label: security-advisories@github.com
  - url: 'https://github.com/opencast/opencast/pull/7736'
    label: security-advisories@github.com
  - url: 'https://github.com/opencast/opencast/releases/tag/19.7'
    label: security-advisories@github.com
  - url: 'https://github.com/opencast/opencast/releases/tag/20.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25
    label: security-advisories@github.com
  - url: >-
      https://github.com/polimediaupv/paella-core/commit/94a36490808ac5a1f60a0745d71ec9253f6d206b
    label: security-advisories@github.com
  - url: >-
      https://github.com/polimediaupv/paella-core/commit/9b2f14ec4cf55efaf4c045c77a5ed8f5ec559ab4
    label: security-advisories@github.com
  - url: >-
      https://github.com/polimediaupv/paella-player/blob/a1b6c42467938a00a4b4d0b8c68435cd4f9d2a16/repos/paella-core/CHANGELOG.md?plain=1#L21
    label: security-advisories@github.com
  - url: >-
      https://github.com/polimediaupv/paella-player/commit/6fe4af7306044198c8e91e2e7f4128428b83cf03
    label: security-advisories@github.com
  - url: >-
      https://github.com/opencast/opencast/security/advisories/GHSA-m6c8-jcw2-5r25
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77615'
  - url: 'https://github.com/advisories/GHSA-m6c8-jcw2-5r25'
tags:
  - nvd
  - cve.org
  - exploit-available
  - ghsa
  - maven
epss: 0.00559
epssPercentile: 0.44211
aliases:
  - GHSA-m6c8-jcw2-5r25
ecosystem: maven
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T01:48:31.414907Z'
ingestedAt: '2026-09-17T21:29:16.985Z'
---

## Overview

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-77615)

Affected packages:

- `org.opencastproject:opencast-engage-paella-player-7 < 19.7`
- `org.opencastproject:opencast-engage-paella-player-7 >= 20.0, < 20.2`
- `paella-core < 1.50.6`

Patched in:

- `org.opencastproject:opencast-engage-paella-player-7 19.7`
- `org.opencastproject:opencast-engage-paella-player-7 20.2`
- `paella-core 1.50.6`

Source: https://github.com/advisories/GHSA-m6c8-jcw2-5r25
