Vulnerability record · CVE-2018-8831 · published 18 April 2018
CVE-2018-8831: Kodi persistent XSS via playlist executes script in victim browser
Kodi · Kodi
Kodi through 17.6 contains a persistent cross-site scripting flaw in how it handles playlists, allowing arbitrary HTML or script to be stored and later executed in the context of the victim user's browser. Because the payload persists, any user who views the affected playlist content can trigger it, making it a reliable vector for browser-side compromise.
Description
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) and exploitation requires user interaction, but public exploit code and a very high EPSS score raise the practical risk.
What it is
Kodi through 17.6 contains a persistent cross-site scripting flaw in how it handles playlists, allowing arbitrary HTML or script to be stored and later executed in the context of the victim user's browser. Because the payload persists, any user who views the affected playlist content can trigger it, making it a reliable vector for browser-side compromise.
Impact
An attacker can execute arbitrary script in the victim's browser session, enabling theft of session data, page manipulation, or redirection to malicious content. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but successful exploitation requires user interaction (UI:R) such as opening or viewing a crafted playlist. No authentication is needed to deliver the payload.
Exploitation
Public exploit code is referenced in Exploit-DB and Full Disclosure, and EPSS is high (0.52652, 98.9th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record here.
What to do
- Upgrade Kodi to a version later than 17.6 that addresses the playlist XSS issue.
- If upgrade is not possible, restrict or disable untrusted playlist sources and avoid opening playlists from unknown origins.
- Apply browser-side protections such as a strict Content Security Policy where Kodi web content is rendered.
- Educate users not to open playlists or media links from untrusted sources.
- Monitor vendor advisory trac.kodi.tv/ticket/17814 for patch guidance.
Detection
- Inspect Kodi playlist files for embedded HTML or script tags that should not appear in media playlists.
- Monitor browser or Kodi logs for unexpected script execution or outbound requests following playlist access.
- Hunt for known exploit payload patterns from the referenced Exploit-DB entry in file or network telemetry.
- Alert on Kodi processes spawning browser sessions or unusual child processes after playlist handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2018/Apr/36 | ExploitMailing ListThird Party Advisory |
| https://trac.kodi.tv/ticket/17814 | Vendor Advisory |
| https://www.exploit-db.com/exploits/44487/ | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2018/Apr/36 | ExploitMailing ListThird Party Advisory |
| https://trac.kodi.tv/ticket/17814 | Vendor Advisory |
| https://www.exploit-db.com/exploits/44487/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-8831 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8831), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.