VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
Brief
Overview
The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2. 45, v2. 103 and earlier, and other v2. x releases that expose the vulnerable mwEmbedLoader. php endpoint.
Until a vendor patch is available, users are advised to restrict access to the affected endpoint or disable it entirely.
Description
Kaltura is an AI video platform that provides tools for video management, publishing, playback, and integration with web applications. Kaltura’s HTML5 player library exposes the mwEmbedLoader. php endpoint, which accepts a user-controlled ServiceUrl parameter as the target URL for backend API requests.
