logo

AVideo Platform Vulnerability Allows Hackers to Hijack Streams via Zero-Click Command Injection

ID: b20808c5-ee3d-59d0-9dae-510c0c1e422b

STIX ID: report--b20808c5-ee3d-59d0-9dae-510c0c1e422b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Divya

...
...

A critical zero-click, unauthenticated OS command injection (CVE-2026-29058, CVSS 9.8) in AVideo (confirmed in v6.0) lets attackers inject decoded base64Url input directly into an ffmpeg shell command—due to missing shell escaping—leading to potential full server takeover; remediation is to upgrade to AVideo 7.0+ (which implements escapeshellarg and safer execution) or apply mitigations like restricting access to objects/getImage.php and deploying WAF rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.