← Back

CVE-2025-69771

nvd nist
Published: Feb 25, 2026Modified: Mar 20, 2026

JSON object

Loading...
9.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 6.0
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-site context, it can bypass cross-origin restrictions, leading to unauthorized same-site API requests and session data exfiltration.

Affected (1)

1 product
Asbplayer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.13.0

References (2)

Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.