PatchDay Alert

CVE

CVE-2026-40911

0field notes · 1digest CVSS 10.0


Daily digests

An unauthenticated attacker can send a crafted WebSocket message to AVideo's YPTSocket plugin, and the server will relay it straight to every connected browser. Two eval() calls on the client side execute the attacker's JavaScript in the context of every viewer, including admins. That means instant session theft, account takeover, and full control of the platform with zero interaction required from victims.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.