@Tinkode, I don't know whether you are the author of the vulnerability but I think it's more ethical to report it before post it. Just a sugerence. I tell you this because youtube offer a fairly good services for free, as well as google, and this kind of stuffs doesn't benefit them at all. I'd have reported rather than divulge it all around the www. Anyway, very good job! How did you reach to the security hole?
I found a article about XSS and HTML5 and I tested on youtube to see if it's vulnerable to XSS. I don't know from when is public this vuln, but I written the article yesterday.
But I don't care who found this. The important thing it's Youtube was vulnerable and "defaced". These things aren't allowed for a company like youtube, a part of google.