🔐 CVE Alert

CVE-2026-35208

UNKNOWN 0.0

lichess.org has an Unsanitized Stream Title Injection on /streamer

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
19th

lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage “Live streams” widget by placing markup in their Twitch/YouTube stream title. CSP is present and blocks inline script execution, but the issue is still a server-side HTML injection sink. To trigger this, a Lichess account only needs to satisfy the normal streamer requirements and get approved. Per Streamer.canApply, that means an account older than 2 days with at least 15 games, or a verified/titled account. After moderator approval, once the streamer goes live, Lichess pulls the platform title and renders it into the UI as-is. No extra privileges are needed beyond a normal approved streamer profile. This vulnerability is fixed with commit 0d5002696ae705e1888bf77de107c73de57bb1b3.

CWE CWE-79 CWE-116
Vendor lichess-org
Product lila
Published Apr 6, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for lichess-org lila

Be the first to know when new unknown vulnerabilities affecting lichess-org lila are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

lichess-org / lila
< 0d5002696ae705e1888bf77de107c73de57bb1b3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/lichess-org/lila/security/advisories/GHSA-v7gh-939r-pfjq github.com: https://github.com/lichess-org/lila/commit/0d5002696ae705e1888bf77de107c73de57bb1b3 vimeo.com: https://vimeo.com/1175908262