Executive brief
AVideo, an open-source video platform, contains a security flaw in its video processing component. An attacker who can generate a valid encrypted request can execute unauthorized commands on the underlying server. This could lead to a complete takeover of the video hosting service, unauthorized access to private media, or disruption of operations.
Technical details
An OS command injection vulnerability exists in AVideo through version 29.0 within the `plugin/API/standAlone/ffmpeg.json.php` endpoint. The root cause is the improper neutralization of the `notifyCode` and `callback` parameters, which are concatenated raw into a shell command string passed to `execAsync()`. While other parameters in the same string are escaped, these two bypass sanitization filters. An attacker capable of crafting a valid encrypted `codeToExec` payload (requiring knowledge of the APISecret and system salt) can inject shell metacharacters to execute arbitrary commands as the web-server user. This vulnerability is a residual flaw following previous hardening of the `ffmpegCommand` parameter.
Affected products
- WWBN AVideo <= 29.0
Timeline
- 2026-07-01: disclosed: Initial disclosure via GitHub Security Advisory
- 2026-07-16: advisory: NVD publication date