CVE-2026-97233

Summary

A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
volotatAnagnorisis0.4.0affected
volotatAnagnorisis0.4.1affected
volotatAnagnorisis0.4.2affected
volotatAnagnorisis0.4.3affected
volotatAnagnorisis0.4.4affected
volotatAnagnorisis0.4.5affected
volotatAnagnorisis0.4.6affected
volotatAnagnorisis0.4.7affected
volotatAnagnorisis0.4.8affected
volotatAnagnorisis0.4.9affected
volotatAnagnorisis0.4.10affected
volotatAnagnorisis0.4.11affected

Weaknesses

  • CWE-79: Cross Site Scripting
  • CWE-94: Code Injection

References