THREAT OPS › Threat News › [NVD] CVE-2026-86188 (HIGH 7.2) — AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names reso
[NVD] CVE-2026-86188 (HIGH 7.2) — AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names reso
CVE-2026-86188 CVSS: 7.2 HIGH Published: 2026-09-05T13:18:13.843
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-86188cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86188