Medium severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-57167
CVE-2026-57167
Description
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages embed a schema.org JSON-LD block by JSON.stringify-ing video metadata without escaping less-than, greater-than, or slash characters, allowing a value containing the byte sequence that closes a script element to inject arbitrary HTML or JavaScript that executes in the instance origin for visitors to the attacker's videos. This issue is fixed in version 8.2.2.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.