CVE-2026-64625

CRITICAL

AVideo before 29.0 OS Command Injection via execAsync

Title source: cna
STIX 2.1

Description

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-rc5x-vh5v-473f)
https://github.com/WWBN/AVideo/security/advisories/GHSA-rc5x-vh5v-473f
Third Party Advisory third-party-advisory
VulnCheck Advisory: AVideo before 29.0 OS Command Injection via execAsync
https://www.vulncheck.com/advisories/avideo-before-os-command-injection-via-execasync

Scores

CVSS v3 9.8
EPSS 0.0035
EPSS Percentile 27.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
WWBN/AVideo < 29.0
Published Jul 20, 2026
Tracked Since Jul 21, 2026