
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39369 is a path traversal vulnerability in WWBN AVideo, an open source video platform, affecting versions 26.0 and prior. The flaw exists in objects/aVideoEncoderReceiveImage.json.php, where an authenticated uploader can supply a crafted same-origin /videos/... URL to bypass traversal scrubbing and read arbitrary server-local files, which are then republished through a public GIF media URL. The vulnerability was published on April 7, 2026, with the GitHub Security Advisory (GHSA-f4f9-627c-jh33) released on April 8, 2026. It carries a CVSS v3.1 base score of 7.6 (High) (GitHub Advisory, AVideo Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), stemming from a flawed traversal sanitization routine in objects/aVideoEncoderReceiveImage.json.php. The code used str_replace('../', '', ...) to strip traversal sequences, which is bypassable using overlapping inputs such as ....// — after stripping ../, the remaining characters reconstitute a valid traversal sequence. The endpoint accepted attacker-controlled downloadURL_gifimage values pointing to same-origin /videos/... URLs; the functions url_get_contents() and try_get_contents_from_local() then resolved these into local filesystem reads, writing the fetched bytes to the GIF destination. A secondary bug caused the invalid-image cleanup routine to reference the wrong variable ($obj->jpgSpegifDestctrumDest instead of $obj->gifDest), meaning non-image payloads were never deleted from disk and remained publicly accessible (AVideo Advisory, Patch Commit).
Successful exploitation allows an authenticated uploader to read arbitrary server-local files — including /etc/passwd, application source code, and deployment-specific configuration files — and expose their contents through a publicly accessible GIF media URL. This results in high confidentiality impact, as sensitive system and application data can be retrieved by any unauthenticated party once published. There is also low integrity and availability impact, as the non-image payload persists on disk in public media storage. Exposed credentials or configuration details could facilitate further attacks, including privilege escalation or lateral movement (AVideo Advisory, GitHub Advisory).
No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of reporting (GitHub Advisory). The vulnerability requires low privileges (authenticated uploader role) and no user interaction, with low attack complexity, making it relatively straightforward to exploit once credentials are obtained. The EPSS score is approximately 0.049% (0.024% per GitHub Advisory), placing it in the 7th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The advisory credits researcher threalwinky with discovery (AVideo Advisory).
downloadURL_gifimage value using overlapping traversal sequences to bypass str_replace('../', '', ...) sanitization, e.g., https://localhost/videos/....//....//....//....//....//....//etc/passwd.POST /objects/aVideoEncoderReceiveImage.json.php
downloadURL_gifimage=https://localhost/videos/....//....//....//....//....//....//etc/passwdGET /objects/videos.json.php?showAll=1 and extract the generated GIF URL from the videosURL.gif.url field in the response./etc/passwd) byte-for-byte, now publicly accessible without authentication (AVideo Advisory)./objects/aVideoEncoderReceiveImage.json.php containing downloadURL_gifimage parameters with patterns like ....// or repeated slash sequences; outbound loopback requests (to localhost or 127.0.0.1) originating from the web server process.aVideoEncoderReceiveImage.json.php with encoded or obfuscated path traversal sequences in the request body; subsequent GET requests to /objects/videos.json.php?showAll=1 from the same source IP shortly after./etc/passwd or PHP source code); unexpected files with .gif extensions whose content does not match valid GIF magic bytes (GIF87a or GIF89a).localhost for paths outside the /videos/ directory tree (AVideo Advisory).The fix is available in the patch commit 2375eb5 for the AVideo repository; users should upgrade to any version incorporating this commit (post-26.0). The patch replaces the bypassable str_replace('../', '', ...) sanitization with URL decoding followed by a strpos($decodedPath, '..') check that rejects any URL whose decoded path contains traversal markers, and also corrects the invalid-image cleanup to reference the correct $gifDest variable. Until patching is possible, administrators should restrict uploader role access to only fully trusted users and consider blocking external access to objects/aVideoEncoderReceiveImage.json.php at the web server or WAF level (Patch Commit, GitHub Advisory).
The vulnerability was reported by researcher threalwinky and published by project maintainer DanielnetoDotCom via GitHub Security Advisory on April 6–8, 2026. Brief coverage appeared on The Hacker Wire and security aggregators such as CVEFeed and VulDB shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (AVideo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."