Blind Server-Side Request Forgery in AVideo by WWBN
CVE-2026-91967

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91967?

AVideo versions prior to 29.0 contain a vulnerability that allows authenticated users with upload permissions to exploit the getHeaderContentTypeFromURL function. This flaw permits the issuing of get_headers() calls, which are only partially safeguarded by format validation. By storing malicious URLs as video links, attackers can trigger the vulnerable function during the rendering of video watch pages, enabling internal host probing through content-type oracles and timing-based detection mechanisms.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.