OS Command Injection Flaw in AVideo by WWBN
CVE-2026-64625

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-64625?

An OS command injection vulnerability exists in AVideo prior to version 29.0 due to an incomplete fix for a previous issue. This vulnerability allows attackers to inject arbitrary operating system commands via the Live plugin's on_publish.php endpoint. The flaw arises from the execAsync() function, which improperly handles command arguments, leading to potential exploitation despite existing protections like escapeshellarg(). This can enable unauthorized command execution, jeopardizing the security of the affected system.

Affected Version(s)

AVideo 0 < 29.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.