AVideo Platform Vulnerability Allows Hackers to Hijack Streams via Zero-Click Command Injection
ID: b20808c5-ee3d-59d0-9dae-510c0c1e422b
STIX ID: report--b20808c5-ee3d-59d0-9dae-510c0c1e422b
Feed Name: GBHackers
Threat Score
A critical zero-click, unauthenticated OS command injection (CVE-2026-29058, CVSS 9.8) in AVideo (confirmed in v6.0) lets attackers inject decoded base64Url input directly into an ffmpeg shell command—due to missing shell escaping—leading to potential full server takeover; remediation is to upgrade to AVideo 7.0+ (which implements escapeshellarg and safer execution) or apply mitigations like restricting access to objects/getImage.php and deploying WAF rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
