Junglewise Threat Intelligence

CVE-2026-45731: WWBN AVideo path traversal in view/update.php

CVE-2026-45731 · Severity: medium · CVSS 3.1 · Published 2026-05-29

Technologies: wwbn/avideo (Packagist), WWBN AVideo. Vendors: Packagist, WWBN.

Executive brief

WWBN AVideo is an open-source platform used for hosting and managing video content. A security flaw allows an authenticated administrator to read sensitive files from the underlying server, such as system configuration files or environment variables. This could lead to the exposure of credentials and other private data, potentially allowing for further compromise of the server environment.

Technical details

A path traversal vulnerability exists in `view/update.php` due to insufficient sanitization of the `updateFile` POST parameter. The application concatenates this user-supplied input into a file path used by PHP's `file()` function during database migrations. An authenticated attacker with administrative privileges can use directory traversal sequences (e.g., `../../`) to bypass the intended `updatedb/` directory and read any text file reachable by the web server process, such as `/etc/passwd` or `.env` files. The vulnerability was verified on the master branch (commit bc03406) and affects versions up to and including 29.0.

Affected products

  • WWBN AVideo 29.0 and earlier

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: NVD publication date

References

Related threats