Home

Description

WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When the initial URL responds with an HTTP redirect (Location header), the redirect target is fetched via fakeBrowser() without re-validation, allowing an attacker to reach internal services (cloud metadata, RFC1918 addresses) through an attacker-controlled redirect. This issue is fixed in version 26.0.

PUBLISHED Reserved 2026-03-17 | Published 2026-03-20 | Updated 2026-03-20 | Assigner GitHub_M




HIGH: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-918: Server-Side Request Forgery (SSRF)

Product status

< 26.0
affected

References

github.com/...AVideo/security/advisories/GHSA-9x67-f2v7-63rw exploit

github.com/...AVideo/security/advisories/GHSA-9x67-f2v7-63rw

github.com/...ommit/0e56382921fc71e64829cd1ec35f04e338c70917

cve.org (CVE-2026-33039)

nvd.nist.gov (CVE-2026-33039)

Download JSON