OS Command Injection Flaw in AVideo by WWBN
CVE-2026-64625
9.3CRITICAL
What is CVE-2026-64625?
An OS command injection vulnerability exists in AVideo prior to version 29.0 due to an incomplete fix for a previous issue. This vulnerability allows attackers to inject arbitrary operating system commands via the Live plugin's on_publish.php endpoint. The flaw arises from the execAsync() function, which improperly handles command arguments, leading to potential exploitation despite existing protections like escapeshellarg(). This can enable unauthorized command execution, jeopardizing the security of the affected system.
Affected Version(s)
AVideo 0 < 29.0
