Vulnerability Description
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-site context, it can bypass cross-origin restrictions, leading to unauthorized same-site API requests and session data exfiltration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Killergerbah | Asbplayer | <= 1.13.0 |
Related Weaknesses (CWE)
References
- https://github.com/killergerbah/asbplayer
- https://reve-offensive.tistory.com/35Third Party Advisory
FAQ
What is CVE-2025-69771?
CVE-2025-69771 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active...
How severe is CVE-2025-69771?
CVE-2025-69771 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-69771?
Check the references section above for vendor advisories and patch information. Affected products include: Killergerbah Asbplayer.