PT-2026-21762 · Avideo · Avideo

Arkmarta

·

Published

2026-02-24

·

Updated

2026-03-01

·

CVE-2026-27732

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 22.0
Description AVideo is an open source video platform. The aVideoEncoder.json.php API endpoint accepts a downloadURL parameter and fetches the referenced resource server-side without proper validation or an allow-list. This allows authenticated users to trigger server-side requests to arbitrary URLs, including internal network endpoints, leading to Server-Side Request Forgery (SSRF). An authenticated attacker can leverage SSRF to interact with internal services and retrieve sensitive data, potentially leading to further compromise. The vulnerable parameter is downloadURL.
Recommendations Update AVideo to version 22.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27732
GHSA-H39H-7CVG-Q7J6

Affected Products

Avideo