AndDone, a security research firm, is credited with discovering two unpatched vulnerabilities in Kaltura's mwEmbed player library. Researcher Gerjan Wemekamp reported the flaws and published a technical writeup detailing the file read and code execution chains. The researcher assigned CVSS scores of 10.0 and 9.1 to the vulnerabilities.