CVE Explorer
CVE-2026-55879
OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads the session JWT from localStorage, and takes ov
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openreplay","vendor":"openreplay","versions":[{"status":"affected","version":">= 1.24.0, < 1.25.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/openreplay/openreplay/commit/ec41f4425a99c478a4418adbd2f094ab6a8b0daf","tags":["x_refsource_MISC"],"url":"https://github.com/openreplay/openreplay/commit/ec41f4425a99c478a4418adbd2f094ab6a8b0daf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/references/1
{"name":"https://github.com/openreplay/openreplay/releases/tag/v1.25.0","tags":["x_refsource_MISC"],"url":"https://github.com/openreplay/openreplay/releases/tag/v1.25.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/references/2
{"name":"https://github.com/openreplay/openreplay/security/advisories/GHSA-3mfc-7hf4-jfxh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openreplay/openreplay/security/advisories/GHSA-3mfc-7hf4-jfxh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b413de2f543104ce8fb76c650ac1d20c37fc86e20f45c9c57af6bf54fa4279 · sha256:38f31130a5419703… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.