GHSA-pgvh-p3g4-86jwCriticalCVSS 9.6

AVideo contains Command injection when embedding a video link

Published
February 2, 2023
Last Modified
June 22, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact:

An attacker could execute remote code on a system running wwbn/avideo

Step to Reproduce:

  1. Go to the My Videos tab

https://demo.avideo.com/mvideos

  1. Click "Embed a video link"

Append a command to the url as a query string. eg. ?whoami

then click Save

This issue has been resolved in commit 236228f15

🎯 Affected products1

  • composer/wwbn/avideo:< 12.4

🔗 References (4)