Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-62613— VDO.Ninja Reflected XSS Vulnerability in control.html

Quick assessment

Affected
steveseguin vdo.ninja
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

vdo.ninja是Steve Seguin个人开发者的一个远程视频输入工具。 vdo.ninja 28.0版本至28.4之前版本存在跨站脚本漏洞,该漏洞源于对examples/control.html中room参数清理不当,可能导致反射型跨站脚本攻击。

AI Predicted 5.4 Difficulty: Easy EPSS 1.08% · P62

Public Exploits 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-62613

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
VDO.Ninja Reflected XSS Vulnerability in control.html
Source: CVE Program / CVE List V5
Vulnerability Description
VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to before 28.4, a reflected Cross-Site Scripting (XSS) vulnerability exists on examples/control.html through the room parameter, which is improperly sanitized before being rendered in the DOM. The application fails to validate and encode user input, allowing malicious scripts to be injected and executed. This issue has been patched in version 28.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5
Vulnerability Title
vdo.ninja 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
vdo.ninja是Steve Seguin个人开发者的一个远程视频输入工具。 vdo.ninja 28.0版本至28.4之前版本存在跨站脚本漏洞,该漏洞源于对examples/control.html中room参数清理不当,可能导致反射型跨站脚本攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
steveseguin vdo.ninja >= 28.0, < 28.4 -

II. Public POCs for CVE-2025-62613

# POC Description Source Link Shenlong Link
1 VDO.Ninja 28.0 to 28.3 contains a reflected XSS caused by improper sanitization of the room parameter in examples/control.html, letting remote attackers execute scripts, exploit requires crafted URL. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-62613.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-62613

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-62613

No comments yet


Leave a comment