Cross-Site Request Forgery and Path Traversal in AVideo
CVE-2026-85160
7.2HIGH
What is CVE-2026-85160?
AVideo, starting from commit c91b5975d, is vulnerable to critical security issues including cross-site request forgery (CSRF) and path traversal. These vulnerabilities arise in the stopLive.php file, allowing attackers to exploit the application by bypassing token validation and using unsanitized parameters. Malicious actors can craft a specifically designed image tag with a traversal payload (e.g., key=../../videos) that triggers recursive directory deletion, putting admin-controlled directories at risk when they visit an affected page.
Affected Version(s)
AVideo 0
