Executive brief
AVideo, an open-source video platform, contains a vulnerability in its Scheduler plugin that allows administrators to make the server send requests to internal network locations. This could allow an attacker with administrative access to steal sensitive cloud credentials or access internal services that are not meant to be reachable from the internet. The issue stems from a failure to properly restrict the web addresses that the scheduler is allowed to contact.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Scheduler plugin of AVideo. The `run()` function in `plugin/Scheduler/Scheduler.php` utilizes `url_get_contents()` on a user-provided `callbackURL` without passing it through the `isSSRFSafeURL()` validation function. While the URL format is checked, it does not block requests to loopback, RFC-1918 private addresses, or cloud metadata endpoints (e.g., 169.254.169.254). An authenticated administrator can exploit this to perform internal port scanning or retrieve sensitive IAM credentials in cloud environments. This vulnerability represents an incomplete patch of previous SSRF fixes in other AVideo components. The issue is addressed in version 26.0.
Affected products
- WWBN AVideo <= 25.0
Timeline
- 2026-03-18: disclosed
- 2026-03-19: advisory
- 2026-03-19: patched