Junglewise Threat Intelligence

CVE-2026-63304: WWBN AVideo OS command injection in listFFmpegProcesses

CVE-2026-63304 · Severity: high · CVSS 8.1 · Published 2026-07-16

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

AVideo, an open-source video platform, contains a security flaw that allows attackers to execute unauthorized commands on the underlying server. By sending a specially crafted request to the platform's API, an attacker can take control of the web server, potentially leading to the theft of customer data, modification of site content, or a complete service outage. This attack requires the attacker to possess the site's API secret, but does not require a standard user login.

Technical details

An OS command injection vulnerability exists in AVideo through version 29.0 within `plugin/API/standAlone/functions.php`. The `listFFmpegProcesses()` function interpolates the `$keyword` parameter directly into a shell command string inside single quotes without proper escaping or sanitization. While the application attempts to sanitize input elsewhere, the `list` and `isKeywordRunning` modes in `ffmpeg.json.php` pass raw, decrypted data from the `codeToExec` payload directly to the vulnerable function. An attacker capable of encrypting a payload with the site's `APISecret` can use a single-quote breakout (e.g., `x'; [command] #`) to achieve arbitrary code execution as the web-server user. As of the advisory date, no official patch is available, though using `escapeshellarg()` on the keyword parameter is the recommended mitigation.

Affected products

  • WWBN AVideo through 29.0

Timeline

  • 2026-07-01: advisory: GitHub Security Advisory GHSA-j44m-77cc-p3cc published
  • 2026-07-16: disclosed: CVE-2026-63304 published to NVD

References

Related threats