Server-Side Request Forgery Flaw in WWBN AVideo Video Platform
CVE-2026-39370

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39370?

AVideo, an open source video platform developed by WWBN, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that affects versions 26.0 and earlier. This flaw involves the handling of user-controlled downloadURL parameters, which can include common media file extensions like .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm. By exploiting this vulnerability, authenticated users can manipulate the upload-by-URL feature to bypass existing SSRF validations, enabling them to exfiltrate sensitive data from the server. This arises from an incomplete resolution to a prior related issue.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.