Unauthenticated script execution via stored User-Agent
Published Jul 8, 2026 · Updated Jul 8, 2026
Stored XSS in AVideo Meet through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 allows remote attackers to run script in privileged browsers. Meet_join_log::log stores an unmatched raw HTTP User-Agent in meet_join_log.user_agent, and getMeetInfo.json.php concatenates it into Participants HTML without output encoding. Exploitation requires an unauthenticated join to a public meeting and occurs when its host or a site administrator opens the participant list.
Summary
What happened
Stored XSS in AVideo Meet through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 allows remote attackers to run script in privileged browsers. Meet_join_log::log stores an unmatched raw HTTP User-Agent in meet_join_log.user_agent, and getMeetInfo.json.php concatenates it into Participants HTML without output encoding. Exploitation requires an unauthenticated join to a public meeting and occurs when its host or a site administrator opens the participant list.
The record
- CVE
- CVE-2026-60092
- Published
- Jul 8, 2026
- Updated
- Jul 8, 2026
- Vendor
- World Wide Broadcast Network
- Product
- AVideo
- Classifications
- CWE-79, T1203
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jul 8, 2026CVE publishedPublication date reported by the CVE source.
- Jul 8, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Affected versions are unavailable in this record. Check the vendor advisory for version and patch details.
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- GHSA-7cqp-7cfv-6c3q end-to-end reproductionfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo