
CVE-2026-35208 http://lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage “Live streams” w… https://www.cve.org/CVERecord?id=CVE-2026-35208
Post summary
The post discloses that approved streamers on lichess.org can inject arbitrary HTML into the /streamer endpoint and the Live Streams homepage, indicating an integrity/ XSS-type vulnerability (CVE-2026-35208).
