SSRF Vulnerability in AVideo Open Source Video Platform
CVE-2026-41060
7.7HIGH
What is CVE-2026-41060?
The AVideo platform, created by WWBN, hosts video content but has a significant vulnerability in versions 29.0 and earlier. The isSSRFSafeURL() function located in objects/functions.php includes a same-domain shortcircuit that enables URLs with hostnames matching webSiteRootURL to evade existing SSRF safeguards. This design flaw permits attackers to exploit this pathway to access arbitrary non-standard ports on the server, allowing them to retrieve sensitive data which can subsequently be saved to paths that are publicly accessible, raising serious security concerns.
Affected Version(s)
AVideo <= 29.0
