Cross-Site Request Forgery and Path Traversal in AVideo
CVE-2026-85160

7.2HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85160?

AVideo, starting from commit c91b5975d, is vulnerable to critical security issues including cross-site request forgery (CSRF) and path traversal. These vulnerabilities arise in the stopLive.php file, allowing attackers to exploit the application by bypassing token validation and using unsanitized parameters. Malicious actors can craft a specifically designed image tag with a traversal payload (e.g., key=../../videos) that triggers recursive directory deletion, putting admin-controlled directories at risk when they visit an affected page.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.