CVE-2026-57167

MEDIUM CVSS 4.0: 5.1 EPSS 0.27%
Updated Jul 10, 2026
Peertube
Parameter Value
CVSS 5.1 (MEDIUM)
Fixed In 8.2.2
Type CWE-80 (Improper Neutralization of Script-Related HTML Tags (XSS))
Vendor Peertube
Public PoC No

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages embed a schema.org JSON-LD block by JSON.stringify-ing video metadata without escaping less-than, greater-than, or slash characters, allowing a value containing the byte sequence that closes a script element to inject arbitrary HTML or JavaScript that executes in the instance origin for visitors to the attacker's videos. This issue is fixed in version 8.2.2.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0