Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN721
_____________________________________________________________________


DATE                : 03/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running PeerTube versions prior to 8.2.1.
 
=====================================================================

https://github.com/Chocobozzz/PeerTube/security/advisories/GHSA-jxwq-h9xv-hr28
_____________________________________________________________________



Improper Neutralization of Script-Related HTML Tags in a Web Page
(Basic XSS) in PeerTube

High
Chocobozzz published GHSA-jxwq-h9xv-hr28

Package
PeerTube

Affected versions
< 8.2.1

Patched versions
8.2.1


Description

Summary

The server-side-rendered video watch pages embed a schema.org JSON-LD
block by JSON.stringify-ing an object that contains video metadata.
Because JSON.stringify does not escape <, >, or /, a value containing
the byte sequence </script> terminates the script element early and
lets an attacker inject arbitrary HTML/JavaScript that executes in the
instance origin.


Impact

An attacker can inject arbitrary HTML/JavaScript that executes in the
instance origin for visitor of attacker's videos.

Patched Versions: 8.2.1


Severity
High

CVE ID
CVE-2026-57167

Weaknesses
Weakness CWE-80


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




