
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33296 is an open redirect vulnerability in WWBN/AVideo, a self-hosted video platform, affecting all versions up to and including 25.0. The flaw resides in view/userLogin.php, where a user-supplied redirectUri GET parameter is reflected unsanitized into an inline JavaScript document.location assignment, enabling unauthenticated attackers to redirect victims to attacker-controlled domains. The vulnerability was disclosed on March 18, 2026, by researcher fg0x0 via the GitHub Advisory Database, and published to the NVD on March 22, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 2.1 (Low) (GitHub Advisory).
The root cause is CWE-601 (URL Redirection to Untrusted Site / Open Redirect). In view/userLogin.php, the redirectUri parameter is passed through a function isSafeRedirectURL() and stored in $safeRedirectUri, which is then embedded directly into a JavaScript setInterval callback as document.location = "<value>" — with no call to json_encode(), htmlspecialchars(), or any JavaScript-context escaping (GitHub Advisory). Protocol-relative URLs such as //evil.com bypass the naive isSafeRedirectURL() check because they carry no explicit scheme, yet browsers resolve them as https://evil.com. Additional bypass vectors include subdomain confusion (e.g., https://trusted.com.evil.com) and path-prefix matching weaknesses. Once the victim closes the login popup, the setInterval callback fires and silently navigates the main page to the attacker's URL (AVideo Security Advisory).
Successful exploitation enables phishing attacks where victims are silently redirected to attacker-controlled domains that visually mimic the legitimate AVideo site, facilitating credential harvesting. The confidentiality and integrity impacts are low — limited to the potential theft of user credentials entered on the spoofed page — and there is no direct availability impact to the AVideo server itself. All users of any AVideo installation running version 25.0 or earlier are potentially affected, as no authentication is required to craft or trigger the malicious redirect (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub Security Advisory, including a crafted malicious URL (https://victim.com/view/userLogin.php?redirectUri=//evil.com) and a Python script that verifies payload reflection in the server response (AVideo Security Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.041% (16th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/view/userLogin.php on a target host.https://victim.com/view/userLogin.php?redirectUri=//evil.com. Alternative bypass payloads include https://trusted.com.evil.com to defeat subdomain-based allowlist checks.import requests
base = "https://victim.com/view/userLogin.php"
payload = "//evil.com"
r = requests.get(base, params={"redirectUri": payload})
assert payload in r.text, "Payload not reflected"
print("Reflected payload found in response")setInterval callback detects win.closed and executes document.location = "//evil.com", silently redirecting the main page./view/userLogin.php containing a redirectUri parameter with values beginning with //, http://, or https:// pointing to external domains; outbound browser navigations from AVideo pages to unexpected external domains./view/userLogin.php?redirectUri=//[external-domain] or similar patterns with external URLs in the redirectUri parameter; referrer headers in attacker-controlled server logs showing victim.com as the origin.The fix was committed by the AVideo maintainer (commit 68d0fbb) and ensures the $safeRedirectUri value is properly encoded using json_encode() before being embedded into the JavaScript context, preventing protocol-relative and other bypass payloads from being injected (AVideo Patch Commit). Administrators should upgrade to AVideo version 26.0 or later as soon as it is available. As interim mitigations, consider implementing a strict allowlist in isSafeRedirectURL() that only permits same-origin relative paths, adding Content-Security-Policy headers to restrict navigation targets, and educating users to verify the URL in their browser address bar before entering credentials (GitHub Advisory).
The vulnerability was reported by researcher fg0x0 and published by AVideo maintainer DanielnetoDotCom on March 18, 2026. A Bluesky post referencing the CVE was noted shortly after NVD publication, indicating some community awareness. No major vendor statements, significant media coverage, or notable researcher commentary beyond the advisory itself have been identified (AVideo Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."