PT-2026-21762 · Avideo · Avideo
Arkmarta
·
Published
2026-02-24
·
Updated
2026-03-01
·
CVE-2026-27732
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 22.0
Description
AVideo is an open source video platform. The
aVideoEncoder.json.php API endpoint accepts a downloadURL parameter and fetches the referenced resource server-side without proper validation or an allow-list. This allows authenticated users to trigger server-side requests to arbitrary URLs, including internal network endpoints, leading to Server-Side Request Forgery (SSRF). An authenticated attacker can leverage SSRF to interact with internal services and retrieve sensitive data, potentially leading to further compromise. The vulnerable parameter is downloadURL.Recommendations
Update AVideo to version 22.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo