Server-Side Request Forgery Vulnerability in AVideo by WWBN
CVE-2026-81678
6.9MEDIUM
What is CVE-2026-81678?
AVideo versions prior to 24.0 are susceptible to a server-side request forgery (SSRF) vulnerability in the isSSRFSafeURL function. This flaw arises from the inability to correctly handle embedded IPv4 addresses formatted as NAT64, 6to4, and Teredo IPv6 transition addresses. Unauthenticated attackers can exploit this vulnerability through the LiveLinks proxy endpoint, effectively bypassing SSRF protections. Such exploitation allows remote access to internal services and sensitive cloud metadata endpoints by encoding private IPv4 targets in transition address formats.
Affected Version(s)
AVideo 0 < 24.0
AVideo 24.0
