VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 23, 2026

AVideo before 29.0 OS Command Injection via execAsync

CVE-2026-64625

Description

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.