Information Disclosure in WWBN AVideo Open Source Video Platform
CVE-2026-40908
5.3MEDIUM
What is CVE-2026-40908?
The WWBN AVideo platform, an open source solution for video content management, is subject to a vulnerability that allows unauthenticated users to access sensitive information. Specifically, the git.json.php file in versions up to 29.0 executes git log -1, returning detailed outputs in JSON format. This includes the deployed commit hash, which can assist in version fingerprinting against known vulnerabilities, alongside developer names, email addresses, and potentially sensitive commit messages. As of the last update, there are no available patches to remediate this issue, leaving users exposed.
Affected Version(s)
AVideo <= 29.0
