CVE-2025-69771

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-site context, it can bypass cross-origin restrictions, leading to unauthorized same-site API requests and session data exfiltration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:killergerbah:asbplayer:*:*:*:*:*:chrome:*:*

History

20 Mar 2026, 19:16

Type Values Removed Values Added
References
  • {'url': 'http://chrome.com', 'tags': ['Not Applicable'], 'source': 'cve@mitre.org'}
  • {'url': 'http://killergerbah.com', 'tags': ['Broken Link'], 'source': 'cve@mitre.org'}
  • () https://github.com/killergerbah/asbplayer -
Summary
  • (es) Una vulnerabilidad de carga arbitraria de archivos en la función de carga de subtítulos de asbplayer v1.13.0 permite a los atacantes ejecutar código arbitrario mediante la carga de un archivo de subtítulos manipulado.
Summary (en) An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows attackers to execute arbitrary code via uploading a crafted subtitle file. (en) Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-site context, it can bypass cross-origin restrictions, leading to unauthorized same-site API requests and session data exfiltration.

02 Mar 2026, 19:37

Type Values Removed Values Added
References () http://chrome.com - () http://chrome.com - Not Applicable
References () http://killergerbah.com - () http://killergerbah.com - Broken Link
References () https://reve-offensive.tistory.com/35 - () https://reve-offensive.tistory.com/35 - Third Party Advisory
First Time Killergerbah asbplayer
Killergerbah
CPE cpe:2.3:a:killergerbah:asbplayer:*:*:*:*:*:chrome:*:*

26 Feb 2026, 20:31

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6

25 Feb 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 16:23

Updated : 2026-03-20 19:16


NVD link : CVE-2025-69771

Mitre link : CVE-2025-69771

CVE.ORG link : CVE-2025-69771


JSON object : View

Products Affected

killergerbah

  • asbplayer
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type