Server-Side Request Forgery Flaw in WWBN AVideo Video Platform
CVE-2026-39370
7.1HIGH
What is CVE-2026-39370?
AVideo, an open source video platform developed by WWBN, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that affects versions 26.0 and earlier. This flaw involves the handling of user-controlled downloadURL parameters, which can include common media file extensions like .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm. By exploiting this vulnerability, authenticated users can manipulate the upload-by-URL feature to bypass existing SSRF validations, enabling them to exfiltrate sensitive data from the server. This arises from an incomplete resolution to a prior related issue.
Affected Version(s)
AVideo <= 26.0
