PT-2025-43408 · Vdo.Ninja · Vdo.Ninja
Published
2025-10-22
·
Updated
2026-02-26
·
CVE-2025-62613
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
VDO.Ninja versions 28.0 through 28.3
Description
VDO.Ninja is a tool used to integrate remote video feeds into studio software via WebRTC. A reflected Cross-Site Scripting (XSS) issue exists in the examples/control.html file through the
room parameter. The application does not properly sanitize input before rendering it in the Document Object Model (DOM), which allows for the injection and execution of malicious scripts.Recommendations
Update to version 28.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vdo.Ninja