AVideo Open Source Video Platform Vulnerability in PayPal Transaction Handling
CVE-2026-39366

6.5MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39366?

The PayPal IPN version 1 handler in AVideo, up to version 26.0, is susceptible to transaction replay attacks due to the absence of transaction deduplication. This flaw enables attackers to resend a legitimate IPN notification multiple times, potentially increasing their wallet balance and renewing subscriptions fraudulently. Although the updated handlers in AVideo implement proper deduplication mechanisms, the v1 handler remains active and referenced in billing plans, posing a risk to users. For further details, refer to the commit and advisory linked.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.