
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33292 is an authorization bypass via path traversal vulnerability in the HLS streaming endpoint (view/hls.php) of WWBN AVideo, an open-source video platform. It allows unauthenticated attackers to stream any private, unlisted, or paid video by exploiting a split-oracle condition in the videoDirectory GET parameter. All AVideo versions up to and including 25.0 are affected; the fix is included in version 26.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory). It was published on March 18, 2026, and added to the NVD on March 22, 2026 (GitHub Advisory).
The root cause is CWE-22 (Path Traversal): the videoDirectory GET parameter in view/hls.php is processed by two independent code paths that interpret the input differently, creating a split-oracle condition. The authorization lookup (getVideoFromFileName in objects/video.php:1685-1688) splits the input on / and uses only the first segment (e.g., public_video) for the database query and permission check. However, the file path construction function (getPathToFile in objects/video.php:4622-4638) preserves the full traversal sequence, ultimately resolving public_video/../private_video/index.m3u8 to /videos/private_video/index.m3u8 on the filesystem. No .. filtering, realpath() validation, or web server path normalization applies to query parameters, leaving the traversal fully exploitable without authentication (GitHub Advisory, AVideo Commit).
Successful exploitation allows any unauthenticated attacker to stream private, unlisted, or paid video content without authorization, resulting in a high confidentiality impact with no integrity or availability effect. Monetized content protected by pay-per-view or subscription gates can be accessed for free, causing direct financial harm to platform operators and content creators. Because video filenames follow predictable patterns (e.g., video_YYYYMMDD_XXXXX), an attacker with access to a single public video can enumerate and exfiltrate the entire video library of an AVideo instance — a risk that applies to virtually all deployments, as having at least one public video is the default configuration (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands and ffmpeg instructions that reproduce the attack against a real AVideo instance (GitHub Advisory). No authentication or special privileges are required, and attack complexity is low, making the vulnerability trivially exploitable by any network-accessible attacker. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.038% (0.074% per the advisory), placing it in the 22nd percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog as of the time of this report.
public_video). Video filenames follow the pattern video_YYYYMMDD_XXXXX, enabling enumeration of additional targets.curl -s "https://target.com/view/hls.php?videoDirectory=private_video" | head -5
# Expected: "HLS.php Can not see video [ID] (private_video) cannot watch (ID)"videoDirectory parameter that uses the known public video name followed by /../ and the target private video name: public_video/../private_video.curl -s "https://target.com/view/hls.php?videoDirectory=public_video/../private_video" \
-H "Accept: application/vnd.apple.mpegurl"
# Expected: Valid M3U8 playlist containing private_video's HLS segmentsThe authorization check passes against public_video (accessible), while the filesystem serves private_video's content.
5. Stream or download the private video: Use the returned M3U8 playlist with an HLS-capable player or ffmpeg to download the full video:
ffmpeg -i "https://target.com/view/hls.php?videoDirectory=public_video/../private_video" \
-c copy stolen_video.mp4/view/hls.php containing ../ sequences in the videoDirectory parameter (e.g., ?videoDirectory=public_video/../private_video); high-volume or automated requests to the HLS endpoint from a single IP, consistent with enumeration of video filenames.hls.php with videoDirectory values containing ..; successful HTTP 200 responses (returning M3U8 content) for videoDirectory values that include traversal sequences referencing non-public video directories._error_log) showing access to video IDs that do not match the videoDirectory first segment, or absence of expected "cannot watch" denial messages for restricted content that was nonetheless served..ts, .m3u8) in the videos storage directory, particularly outside of normal user activity hours (GitHub Advisory).Upgrade AVideo to version 26.0 or later, which includes the security fix committed by the maintainer (commit bc03406) (AVideo Commit). The patch adds .. detection and rejection at the top of view/hls.php and a realpath() boundary check in getPathToFile() to ensure resolved paths remain within the videos directory. As a temporary workaround if immediate upgrade is not possible, add input sanitization to view/hls.php to reject any videoDirectory value containing .., and implement rate limiting on the HLS streaming endpoint to slow enumeration attacks. Additionally, consider replacing predictable video filename patterns with randomized, non-enumerable identifiers to reduce the attack surface (GitHub Advisory).
The vulnerability was reported by a researcher identified as "offset" and published by AVideo maintainer DanielnetoDotCom on March 18, 2026 (GitHub Advisory). Community discussion was noted on Bluesky shortly after disclosure, and several vulnerability intelligence platforms (VulDB, CIRCL, Tenable, INCIBE) indexed the CVE within days of publication. A technical write-up was published by Infinit Security detailing the authorization bypass mechanism (Feedly). Overall community reaction highlighted the severity of the split-oracle design flaw and the ease of exploitation given predictable filename patterns.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."