PT-2026-30989 · Avideo · Avideo

Threalwinky

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-39370

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description AVideo, an open source video platform, has a Server-Side Request Forgery (SSRF) issue in the objects/aVideoEncoder.json.php file. Attackers can control the downloadURL parameter, using common media or archive extensions like .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm, to bypass SSRF validation. The server then retrieves the response and saves it as media content. This allows an authenticated uploader to use the upload-by-URL flow to reliably exfiltrate data via SSRF. This is due to an incomplete fix for a previously identified issue.
Recommendations Update AVideo to a version later than 26.0.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-39370
GHSA-CMCR-Q4JF-P6Q9

Affected Products

Avideo