shaka-player is vulnerable to CSS Injection
30
Low Risk
Affected versions of this package are vulnerable to a CSS injection issue in TTML subtitle rendering, where untrusted backgroundImage values are concatenated into a CSS url() expression without proper sanitization. An attacker able to supply a crafted TTML subtitle through an untrusted HLS or DASH stream can break out of the url() context using malicious characters such as single quotes and inject arbitrary CSS. This may enable data exfiltration via CSS selectors, UI redressing, or manipulation of page elements in applications embedding Shaka Player.
You are affected if you are using a version that falls within the vulnerable range.
shaka-player is vulnerable to CSS Injection in versions 4.0.0 - 4.15.37, 4.16.0 - 4.16.25 and 5.0.0 - 5.0.9.
Upgrade the shaka-player library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant