{"id":"GHSA-2hfj-cxw7-g45p","summary":"Unsafe inline XSS in pasting DOM element into chat","details":"### Impact\n\nInline scripts are executed when Javascript is parsed via a paste action.\n\n1. Open https://watch.owncast.online/\n2. Copy and then paste `\u003cimg src=null onerror=alert('hello')\u003e` into the\nchat field.\n3. An alert should pop up.\n\n### Patches\n```\n    ⋮ 13 │    // Content security policy\n    ⋮ 14 │    csp := []string{\n    ⋮ 15 │        \"script-src 'self' 'sha256-2HPCfJIJHnY0NrRDPTOdC7AOSJIcQyNxzUuut3TsYRY='\",\n    ⋮ 16 │        \"worker-src 'self' blob:\", // No single quotes around blob:\n    ⋮ 17 │    }\n```\n\nWill be patched in 0.0.9 by blocking `unsafe-inline` Content Security Policy and specifying the `script-src`.  The `worker-src` is required to be set to `blob` for the video player.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [owncast/owncast](https://github.com/owncast/owncast/issues)\n* Email us at [gabek@real-ity.com](mailto:gabek@real-ity.com)\n","aliases":["CVE-2021-39183","GO-2022-0291"],"modified":"2026-05-07T05:01:16.193274326Z","published":"2021-12-14T21:48:16Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-12-14T20:16:10Z","nvd_published_at":"2021-12-14T20:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/owncast/owncast/security/advisories/GHSA-2hfj-cxw7-g45p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39183"},{"type":"PACKAGE","url":"https://github.com/owncast/owncast"}],"affected":[{"package":{"name":"github.com/owncast/owncast","ecosystem":"Go","purl":"pkg:golang/github.com/owncast/owncast"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-2hfj-cxw7-g45p/GHSA-2hfj-cxw7-g45p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L"}]}