Description
VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to before 28.4, a reflected Cross-Site Scripting (XSS) vulnerability exists on examples/control.html through the room parameter, which is improperly sanitized before being rendered in the DOM. The application fails to validate and encode user input, allowing malicious scripts to be injected and executed. This issue has been patched in version 28.4.
INFO
Published Date :
2025-10-22T20:52:57.758Z
Last Modified :
2025-10-23T17:28:12.445Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-62613 vulnerability.
| Vendors | Products |
|---|---|
| Vdoninja |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-62613.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability