OAuth Vulnerability in AVideo Open Source Video Platform
CVE-2026-43875
6.8MEDIUM
What is CVE-2026-43875?
An OAuth vulnerability exists in the AVideo open source video platform that allows attackers to bypass password hashing during the authentication process. When a user logs in, a redirect URL may expose their password hash due to improper handling of OAuth login responses. This vulnerability enables attackers to capture sensitive credentials through server logs or browser histories, potentially leading to full account takeover, including access to admin accounts. A patch for this issue has been implemented in later versions of AVideo.
Affected Version(s)
AVideo <= 29.0
