Executive brief
AVideo, an open-source video platform, contains a security flaw that allows administrators to force the server to make unauthorized requests to internal systems. An attacker with administrative access could use this to steal sensitive cloud credentials (like AWS IAM keys) or access private internal databases and services that are not normally exposed to the internet. This could lead to a broader breach of the organization's cloud infrastructure or internal network.
Technical details
A full-read Server-Side Request Forgery (SSRF) exists in AVideo through version 27.0 within the 'plugin/Live/test.php' component. The 'statsURL' parameter is processed using functions like file_get_contents(), curl_exec(), or wget without proper validation against the application's internal 'isSSRFSafeURL()' filter. While the endpoint requires administrative authentication, it lacks CSRF protection, potentially allowing for blind SSRF via cross-site attacks. An attacker can bypass network segmentation to reach localhost, private IP ranges (10.x, 192.168.x), and cloud metadata services (169.254.169.254) to exfiltrate IAM credentials or internal service responses. As of the advisory date, no official patch is confirmed, though manual remediation involves implementing the 'isSSRFSafeURL()' check in the affected file.
Affected products
- WWBN AVideo <= 27.0
Timeline
- 2026-03-23: advisory: Initial GitHub security advisory published
- 2026-06-20: disclosed: CVE published to NVD dataset