Junglewise Threat Intelligence

CVE-2026-46337: WWBN AVideo path traversal in image404Raw.php

CVE-2026-46337 · Severity: medium · CVSS 3.1 · Published 2026-05-29

Technologies: wwbn/avideo (Packagist), WWBN AVideo. Vendors: Packagist, WWBN.

Executive brief

WWBN AVideo is an open-source platform used for hosting and sharing video content. A security flaw allows unauthorized individuals to bypass privacy controls and view private images stored on the server, such as user profile photos, video thumbnails, and poster frames. This could lead to the exposure of sensitive user data and private media that was intended to be restricted to specific users or administrators.

Technical details

A path traversal vulnerability exists in the `view/img/image404Raw.php` endpoint of WWBN AVideo. The script takes the `image` GET parameter and concatenates it directly into a filesystem path used by the `readfile()` function without proper sanitization or validation against the intended directory. While the application performs a `getimagesize()` check, this only verifies that the file's magic bytes match a known image format and does not prevent directory traversal. An unauthenticated attacker can use `..` sequences to access private profile photos, admin-uploaded thumbnails, or images in sibling directories on the server. As of the advisory date, no official patch has been released.

Affected products

  • WWBN AVideo <= 29.0

Timeline

  • 2026-05-12: other: Vulnerability discovered
  • 2026-05-13: disclosed: Advisory published on GitHub
  • 2026-05-29: advisory: CVE published in NVD

References

Related threats