Server-Side Request Forgery Vulnerability in AVideo by WWBN
CVE-2026-85163
7.1HIGH
What is CVE-2026-85163?
AVideo has a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to access arbitrary internal URLs. By manipulating the epg_link parameter during video uploads, attackers can bypass server-side verification, leading to potential exposure of sensitive internal information. This vulnerability highlights the need for robust validation mechanisms to prevent unauthorized internal access during EPG generation.
Affected Version(s)
AVideo 0
