CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-55879

Critical · CVSS 9.3

OpenReplay — Stored Cross-Site Scripting (XSS) via unsanitized custom event names and page URLs rendered in authenticated dashboard

CVSS
9.3
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-79

Description

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads the session JWT from localStorage, and takes over a dashboard account. This issue is fixed in version 1.25.0.

Search profile — drives PoC discovery

Symbols TextEllipsisevent-details modallocalStoragesession JWTcustom event namescaptured page URLsClickHousepublic project keytracking SDKec41f4425a99c478a4418adbd2f094ab6a8b0daf
Keywords CVE-2026-55879GHSA-3mfc-7hf4-jfxhOpenReplay stored XSSOpenReplay XSS dashboardOpenReplay custom event XSSOpenReplay session JWT theftOpenReplay 1.24.0 XSSOpenReplay ClickHouse XSSOpenReplay unauthenticated stored XSSOpenReplay tracking SDK XSS
Versions: >=1.24.0, <1.25.0

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z