CVE-2026-45580
📛 CVE Title
(no title)
Description
AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 5.4 / 10
- CVSS vector
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N- Effective score
- 5.4 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45580
NVD / KEV / EPSS data refreshed 2026-05-25 00:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-33311 - Assigner
- GitHub_M
- Published
- May 29, 2026, 1:14:49 PM
- Updated
- Jun 2, 2026, 1:09:49 AM
- EUVD base score (CVSS 3.1)
-
5.4 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - EUVD-reported EPSS
- 0.1400
- Vendors
- WWBN
- Products
-
AVideo (≤ 29.0)
- Aliases
-
GHSA-m5j4-7r85-2cj2
ENISA description: WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canStream user can persist a key containing " plus an event handler via plugin/Live/saveLive.php, and any visitor (logged in or anonymous) opening the stream's live page executes attacker JavaScript in the platform origin.
EUVD references (1)
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (4)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/WWBN/AVideo/security/advisories/GHSA-m5j4-7r85-2cj2 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45580 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45580 tenable:www.cve.org
Remediations (10)
-
web:api.msrc.microsoft.com
The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.\n \nWe are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. \n\n**Mitigation FAQs**\n\n**Should I leverage the temporary ...
2026-05-26 03:08 UTC -
web:aviatrix.ai
Microsoft addresses the YellowKey vulnerability ( CVE - 2026 -45585) that allows physical bypass of BitLocker encryption in Windows 11 and Server 2025.
2026-05-26 03:08 UTC -
web:cyberpress.org
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, issuing an urgent remediation directive for federal agencies with a due date of June 3, 2026 .
2026-05-26 03:08 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-26 03:08 UTC -
web:jamesvincent.co.uk
On the 19th of May, Microsoft released a mitigation guide for the Windows BitLocker Security Feature Bypass Vulnerability, dubbed YellowKey. YellowKey ( CVE - 2026 -45585) is a Windows BitLocker bypass vulnerability that abuses the Windows Recovery Environment (WinRE) to grant an attacker with physical access unauthorised access to encrypted drives ...
2026-05-26 03:08 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-26 03:08 UTC -
web:securityarsenal.com
Microsoft releases mitigation for CVE - 2026 -45585 (YellowKey). Defenders must act now to block BitLocker bypass risks on Windows.
2026-05-26 03:08 UTC -
web:windowsforum.com
Microsoft has published CVE - 2026 -45585 as a Windows BitLocker security feature bypass vulnerability, with mitigation guidance that tells administrators to mount each device's Windows Recovery Environment image, remove an autofstx.exe entry from WinRE's BootExecute registry value, commit the...
2026-05-26 03:08 UTC -
web:www.notebookcheck.net
Microsoft released mitigation steps for YellowKey ( CVE - 2026 -45585), a BitLocker bypass that grants physical attackers access to encrypted Windows drives.
2026-05-26 03:08 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE - 2026 -45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.