CVE-2026-39369: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-39369 is a path traversal vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in objects/aVideoEncoderReceiveImage.json.php, where an authenticated uploader can supply a crafted same-origin /videos/... URL to bypass traversal scrubbing and read arbitrary server-local files, which are then republished through a public GIF media URL. The vulnerability was published on April 7, 2026, with the GitHub Security Advisory (GHSA-f4f9-627c-jh33) released on April 8, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), stemming from a flawed traversal sanitization routine in objects/aVideoEncoderReceiveImage.json.php. The code used str_replace('../', '', ...) to strip traversal sequences, which is bypassable using overlapping inputs such as ....// — after stripping ../, the remaining characters reconstitute a valid traversal sequence. The endpoint accepted attacker-controlled downloadURL_gifimage values pointing to same-origin /videos/... URLs; the functions url_get_contents() and try_get_contents_from_local() then resolved these into local filesystem reads, writing the fetched bytes to the GIF destination. A secondary bug caused the invalid-image cleanup routine to reference the wrong variable ($obj->jpgSpegifDestctrumDest instead of $obj->gifDest), meaning non-image payloads were never deleted from disk and remained publicly accessible (AVideo Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated uploader to read arbitrary server-local files — including /etc/passwd, application source code, and deployment-specific configuration files — and expose their contents through a publicly accessible GIF media URL. This results in high confidentiality impact, as sensitive system and application data can be retrieved by any unauthenticated party once published. There is also low integrity and availability impact, as the non-image payload persists on disk in public media storage. Exposed credentials or configuration details could facilitate further attacks, including privilege escalation or lateral movement (AVideo Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of reporting (GitHub Advisory). The vulnerability requires low privileges (authenticated uploader role) and no user interaction, with low attack complexity, making it relatively straightforward to exploit once credentials are obtained. The EPSS score is approximately 0.049% (0.024% per GitHub Advisory), placing it in the 7th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The advisory credits researcher threalwinky with discovery (AVideo Advisory).

Exploitation steps

  1. Authenticate: Log in to the AVideo instance with an account that has uploader privileges.
  2. Create a video row: Use the normal encoder flow to create an owned video entry, establishing the context required for the GIF poster endpoint.
  3. Craft the traversal payload: Construct a downloadURL_gifimage value using overlapping traversal sequences to bypass str_replace('../', '', ...) sanitization, e.g., https://localhost/videos/....//....//....//....//....//....//etc/passwd.
  4. Send the malicious POST request: Submit the crafted request to the vulnerable endpoint:
    POST /objects/aVideoEncoderReceiveImage.json.php
    downloadURL_gifimage=https://localhost/videos/....//....//....//....//....//....//etc/passwd
  5. Retrieve the GIF URL: Query GET /objects/videos.json.php?showAll=1 and extract the generated GIF URL from the videosURL.gif.url field in the response.
  6. Download the exfiltrated file: Fetch the GIF URL — the response body will contain the target local file (e.g., /etc/passwd) byte-for-byte, now publicly accessible without authentication (AVideo Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /objects/aVideoEncoderReceiveImage.json.php containing downloadURL_gifimage parameters with patterns like ....// or repeated slash sequences; outbound loopback requests (to localhost or 127.0.0.1) originating from the web server process.
  • Logs: Web server access logs showing POST requests to aVideoEncoderReceiveImage.json.php with encoded or obfuscated path traversal sequences in the request body; subsequent GET requests to /objects/videos.json.php?showAll=1 from the same source IP shortly after.
  • File System: GIF files in the AVideo media/videos directory containing non-image content (e.g., plaintext resembling /etc/passwd or PHP source code); unexpected files with .gif extensions whose content does not match valid GIF magic bytes (GIF87a or GIF89a).
  • Process: Web server worker processes making internal HTTP requests to localhost for paths outside the /videos/ directory tree (AVideo Advisory).

Mitigation and workarounds

The fix is available in the patch commit 2375eb5 for the AVideo repository; users should upgrade to any version incorporating this commit (post-26.0). The patch replaces the bypassable str_replace('../', '', ...) sanitization with URL decoding followed by a strpos($decodedPath, '..') check that rejects any URL whose decoded path contains traversal markers, and also corrects the invalid-image cleanup to reference the correct $gifDest variable. Until patching is possible, administrators should restrict uploader role access to only fully trusted users and consider blocking external access to objects/aVideoEncoderReceiveImage.json.php at the web server or WAF level (Patch Commit, GitHub Advisory).

Community reactions

The vulnerability was reported by researcher threalwinky and published by project maintainer DanielnetoDotCom via GitHub Security Advisory on April 6–8, 2026. Brief coverage appeared on The Hacker Wire and security aggregators such as CVEFeed and VulDB shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (AVideo Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management