Stream Hijacked: Critical Zero-Click Command Injection Flaw Exposed in AVideo-Encoder
ID: 24c4421a-2a3e-5e44-9cfd-19088ec6d829
STIX ID: report--24c4421a-2a3e-5e44-9cfd-19088ec6d829
Feed Name: securityonline.info
Threat Score
**Critical unauthenticated RCE (CVE-2026-29058, CVSS 9.8)** was disclosed in AVideo-Encoder: an unsafe use of a decoded base64Url GET parameter in objects/getImage.php inserts attacker-controlled data into a double-quoted ffmpeg shell command without proper escaping, enabling command injection and full system compromise; vendor patches are available and immediate mitigations include applying updates, IP allowlisting/WAF protections, or disabling the vulnerable endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
