securityonline.info 8/25/2026, 5:30:56 PM · external

Kaltura HTML5 Player flaw lets attackers read files, run code

Kaltura HTML5 Player flaw lets attackers read files, run code
CyberSIXT Evidence Panel
Primary Source kb.cert.org

A critical alert has been issued regarding two unpatched vulnerabilities in the Kaltura HTML5 Player Library. These vulnerabilities, identified in the mwEmbedLoader.php endpoint, can allow unauthenticated attackers to read local files and execute arbitrary code. Attackers can gain control over affected web servers, potentially stealing sensitive data such as database credentials and API keys.

The flaws result from an insecure deserialization process within the KalturaClient library, allowing remote code execution through malicious input. Affected versions include html5lib version 2.45 and earlier versions. Administrators are advised to restrict access to the vulnerable endpoint and enforce an allow-list for URLs due to the lack of official patches.

View Primary Source Via securityonline.info

Article by CyberSIXT