Executive brief
WWBN AVideo is an open-source video streaming and sharing platform. A security vulnerability in the Live plugin allows an authenticated user with streaming permissions to execute arbitrary commands on the underlying server. This could lead to a complete system takeover, unauthorized access to private videos, or the theft of sensitive configuration data and API keys.
Technical details
An OS command injection vulnerability exists in `plugin/Live/on_publish.php` within the YPTSocket notification branch. The application constructs a shell command for `execAsync()` by concatenating variables (including `$m3u8` and `$users_id`) wrapped in literal single quotes without using `escapeshellarg()`. An attacker can inject a single quote to break out of the literal string and append arbitrary shell commands. This can be triggered by an authenticated user who can control their stream key (e.g., via `saveLive.php`), which is then used to generate the `$m3u8` URL. The endpoint is directly reachable via HTTP POST, bypassing typical RTMP restrictions. Successful exploitation results in arbitrary code execution as the web server user.
Affected products
- WWBN AVideo <= 29.0
Timeline
- 2026-05-11: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE published to NVD