OS Command Injection in AVideo by WWBN
CVE-2026-63305
9.2CRITICAL
What is CVE-2026-63305?
AVideo, a popular video-sharing platform, has been found to contain a vulnerability that allows for OS command injection through its ffmpeg.json.php endpoint. In versions up to 29.0, the parameters notifyCode and callback are improperly concatenated into a shell command without adequate escaping. This flaw enables attackers capable of crafting a suitable encrypted payload to inject malicious shell metacharacters, potentially allowing them to execute arbitrary operating system commands under the privileges of the web server user.
Affected Version(s)
AVideo 0 <= 29.0
