Executive brief
AVideo, an open-source video platform, contains a security flaw that allows attackers to execute unauthorized commands on the underlying server. By sending a specially crafted request to the platform's API, an attacker can take control of the web server, potentially leading to the theft of customer data, modification of site content, or a complete service outage. This attack requires the attacker to possess the site's API secret, but does not require a standard user login.
Technical details
An OS command injection vulnerability exists in AVideo through version 29.0 within `plugin/API/standAlone/functions.php`. The `listFFmpegProcesses()` function interpolates the `$keyword` parameter directly into a shell command string inside single quotes without proper escaping or sanitization. While the application attempts to sanitize input elsewhere, the `list` and `isKeywordRunning` modes in `ffmpeg.json.php` pass raw, decrypted data from the `codeToExec` payload directly to the vulnerable function. An attacker capable of encrypting a payload with the site's `APISecret` can use a single-quote breakout (e.g., `x'; [command] #`) to achieve arbitrary code execution as the web-server user. As of the advisory date, no official patch is available, though using `escapeshellarg()` on the keyword parameter is the recommended mitigation.
Affected products
- WWBN AVideo through 29.0
Timeline
- 2026-07-01: advisory: GitHub Security Advisory GHSA-j44m-77cc-p3cc published
- 2026-07-16: disclosed: CVE-2026-63304 published to NVD