Critical severity9.3NVD Advisory· Published Mar 23, 2026· Updated Jun 17, 2026
CVE-2026-33502
CVE-2026-33502
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in plugin/Live/test.php allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/internal services and, when reachable, access internal HTTP resources or cloud metadata endpoints. Commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wwbn/avideoPackagist | <= 26.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/WWBN/AVideo/commit/1e6cf03e93b5a5318204b010ea28440b0d9a5ab3nvdPatchWEB
- github.com/WWBN/AVideo/security/advisories/GHSA-3fpm-8rjr-v5mcnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-3fpm-8rjr-v5mcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33502ghsaADVISORY
News mentions
0No linked articles in our index yet.