
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33237 is a Server-Side Request Forgery (SSRF) vulnerability in the Scheduler plugin of AVideo (wwbn/avideo), a self-hosted video platform. The flaw exists in plugin/Scheduler/Scheduler.php where the run() function processes an admin-configurable callbackURL without applying the isSSRFSafeURL() validation check, allowing requests to internal network addresses and cloud metadata endpoints. All AVideo versions up to and including 25.0 are affected; version 26.0 contains the fix. The vulnerability was disclosed on March 18, 2026, published to the GitHub Advisory Database on March 19, 2026, and assigned a CVSS v3.1 base score of 5.5 (Moderate) (GitHub Advisory, AVideo Advisory).
The root cause is CWE-918 (Server-Side Request Forgery): the Scheduler plugin's run() function at plugin/Scheduler/Scheduler.php:157-166 validates the callbackURL only with isValidURL(), which uses PHP's filter_var($url, FILTER_VALIDATE_URL) to check URL syntax but does not block private or link-local network targets. The critical missing control is isSSRFSafeURL() — a function already present in objects/functions.php that explicitly blocks loopback (127.x.x.x, ::1), RFC-1918 private ranges (10.x.x.x, 172.16-31.x.x, 192.168.x.x), link-local addresses (169.254.x.x including the AWS/GCP/Azure metadata endpoint at 169.254.169.254), and IPv6 private ranges. This check was added to other AVideo endpoints in prior SSRF fixes (GHSA-9x67-f2v7-63rw for the LiveLinks proxy and GHSA-h39h-7cvg-q7j6 for the aVideoEncoder download flow), but the Scheduler plugin was overlooked in both fix waves, constituting an incomplete patch. Exploitation requires an authenticated admin session to configure a scheduled task with a malicious callbackURL and trigger it via the Scheduler's "Run now" interface (GitHub Advisory, AVideo Advisory).
A successful exploit allows an authenticated administrator to cause the AVideo server to issue arbitrary HTTP requests to internal network resources. The most severe impact in cloud-hosted deployments (AWS, GCP, Azure) is theft of IAM instance role credentials from the metadata service at 169.254.169.254, which can enable privilege escalation and lateral movement within the cloud environment. Additionally, the attacker can probe internal APIs, microservices, or databases with HTTP interfaces that are not exposed to the internet, with the server's response stored in the Scheduler execution log and retrievable by the attacker. Availability is not directly impacted, but confidentiality is highly affected and integrity is marginally affected through potential misuse of stolen credentials (GitHub Advisory).
A concrete, step-by-step proof-of-concept (PoC) using curl commands is publicly available in the GitHub security advisory, demonstrating how to create a malicious scheduled task, trigger execution, and retrieve cloud IAM credentials from the Scheduler log (AVideo Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.026% (6th percentile), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
admin_session) for the target AVideo instance running version ≤ 25.0.callbackURL pointing to the AWS cloud metadata service:curl -b "admin_session=<session>" -X POST \
https://target.avideo.site/plugin/Scheduler/View/Scheduler_commands/add.json.php \
-d "callbackURL=http://169.254.169.254/latest/meta-data/iam/security-credentials/&status=a&type=&date_to_execute=2026-03-18+12:00:00"curl -b "admin_session=<session>" \
https://target.avideo.site/plugin/Scheduler/run.phpcurl -b "admin_session=<session>" \
https://target.avideo.site/plugin/Scheduler/View/Scheduler_commands/get.json.php169.254.169.254 (cloud metadata service) or RFC-1918 private IP ranges; unexpected connections to internal microservices or databases originating from the web application process./plugin/Scheduler/View/Scheduler_commands/add.json.php with callbackURL parameters containing 169.254.x.x, 10.x.x.x, 172.16-31.x.x, 192.168.x.x, or 127.x.x.x; GET requests to /plugin/Scheduler/run.php followed by /plugin/Scheduler/View/Scheduler_commands/get.json.php in close succession.get.json.php) containing cloud metadata API responses, IAM credential JSON blobs, or internal service responses.Scheduler::run SSRF protection blocked callbackURL: messages (present only after patching; absence of these on unpatched systems may indicate exploitation attempts went undetected) (AVideo Advisory).Upgrade AVideo to version 26.0 or later, which adds isSSRFSafeURL() validation to the Scheduler's callbackURL before url_get_contents() is called (commit df926e5) (Patch Commit). As a workaround for deployments that cannot immediately upgrade, restrict administrative access to the Scheduler plugin to trusted users only, and apply network-level egress filtering to block outbound requests from the AVideo server to 169.254.169.254 and RFC-1918 ranges. In cloud environments, consider using IMDSv2 (which requires session-oriented requests) on AWS to reduce metadata service exposure, or apply IAM policies that limit the blast radius of any stolen instance role credentials (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."