logo

Stream Hijacked: Critical Zero-Click Command Injection Flaw Exposed in AVideo-Encoder

ID: 24c4421a-2a3e-5e44-9cfd-19088ec6d829

STIX ID: report--24c4421a-2a3e-5e44-9cfd-19088ec6d829

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Ddos

...
...

**Critical unauthenticated RCE (CVE-2026-29058, CVSS 9.8)** was disclosed in AVideo-Encoder: an unsafe use of a decoded base64Url GET parameter in objects/getImage.php inserts attacker-controlled data into a double-quoted ffmpeg shell command without proper escaping, enabling command injection and full system compromise; vendor patches are available and immediate mitigations include applying updates, IP allowlisting/WAF protections, or disabling the vulnerable endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.