Executive brief
WWBN AVideo, an open-source video sharing platform, contains a security flaw that allows users with upload permissions to access sensitive files on the server. By submitting a specially crafted web address during the video upload process, an attacker can trick the system into reading internal system files (like password files or application source code) and making them publicly available as image files. This could lead to the exposure of administrative credentials or other private server data.
Technical details
A path traversal vulnerability exists in 'objects/aVideoEncoderReceiveImage.json.php' due to insufficient sanitization of the 'downloadURL_gifimage' parameter. The application attempted to scrub traversal sequences using a simple string replacement of '../', which was easily bypassed using overlapping sequences like '....//'. When an authenticated uploader provides a crafted same-origin URL, the 'url_get_contents()' and 'try_get_contents_from_local()' functions resolve the request into a local filesystem read. The resulting data is written to a GIF destination path on disk, and because the invalid-image cleanup routine failed to target the correct path, the sensitive file contents remain publicly accessible via a standard media URL. This allows for the disclosure of files such as /etc/passwd or application source code.
Affected products
- WWBN AVideo <= 26.0
Timeline
- 2026-04-06: advisory: GitHub Security Advisory GHSA-f4f9-627c-jh33 published
- 2026-04-07: disclosed: CVE-2026-39369 published
- 2026-04-07: patched: Fix committed to WWBN/AVideo repository