AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()
Published Mar 23, 2026
8.1
HIGHCVSS 3.1
EPSS 4.65%
Description
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous shell metacharacters (`&&`, `;`, `|`, `` ` ``, `<`, `>`). However, it fails to strip `$()` (bash command substitution syntax). Since the sanitized command is executed inside a double-quoted `sh -c` context in `execAsync()`, an attacker who can craft a valid encrypted payload can achieve arbitrary command execution on the standalone encoder server. Commit 25c8ab90269e3a01fb4cf205b40a373487f022e1 contains a patch.
Affected products
-
- Version <= 26.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/WWBN/AVideo/commit/25c8ab90269e3a01fb4cf205b40a373487f022e1 x_refsource_MISCPatch
- https://github.com/WWBN/AVideo/security/advisories/GHSA-pmj8-r2j7-xg6c x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://github.com/advisories/GHSA-pmj8-r2j7-xg6c Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33482
| Link | Providers | Tags |
|---|---|---|
| https://github.com/WWBN/AVideo/commit/25c8ab90269e3a01fb4cf205b40a373487f022e1 | x_refsource_MISCPatch | |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-pmj8-r2j7-xg6c | x_refsource_CONFIRMExploitMitigationVendor Advisory | |
| https://github.com/advisories/GHSA-pmj8-r2j7-xg6c | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-33482 |
Change history (0)
No recorded changes yet.