MEDIUM
Lichess
CVE published 2026-04-06
CVE-2026-35208
A server-side HTML injection vulnerability exists in Lichess, a free, adless, and open-source chess server. The issue allows approved streamers to inject arbitrary HTML into the /streamer and homepage 'Live streams' widget by placing markup in their Twitch/YouTube stream title. Although CSP is present and blocks inline script execution, the issue remains a server-side HTML injection sink. To trigger this, [truncated]