Junglewise Threat Intelligence

CVE-2026-85164: WWBN AVideo server-side request forgery in set_api_userImages

CVE-2026-85164 · Severity: high · CVSS 7.1 · Published 2026-09-03

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video hosting and streaming platform. The set_api_userImages API endpoint contains a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to fetch internal URLs (such as AWS metadata services) and write the responses to publicly accessible web paths. An attacker with a valid API secret can retrieve sensitive cloud credentials and internal service information without authorization.

Technical details

The vulnerability is a server-side request forgery (SSRF) in the set_api_userImages API endpoint (objects/user.php). The url_get_contents() function calls file_get_contents() on user-supplied profileImg and backgroundImg URLs without validating them through the isSSRFSafeURL() check (which is only applied to redirect hops, not the initial request). Authenticated API clients can supply internal URLs (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/) to fetch cloud metadata and internal services. The responses are then written to publicly accessible web paths (videos/userPhoto/photo*.png and videos/userPhoto/background*.jpg) where any unauthenticated attacker can retrieve them. The vulnerability requires a valid API secret and network-reachable API endpoint, but no user interaction. Patches have not yet been released as of the advisory date.

Affected products

  • WWBN AVideo through commit c91b5975d

Timeline

  • 2026-08-19: disclosed: GitHub Security Advisory published
  • 2026-09-03: advisory: NVD and public advisories published

References

Related threats