Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-64625: AVideo < 29.0: Attackers can run arbitrary system commands

CVE-2026-64625 CVE-2026-64625
Summary

AVideo versions before 29.0 have a security flaw that allows hackers to execute malicious system commands. This could lead to unauthorized access or data theft. Update to version 29.0 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
wwbn avideo < 29.0
Original title
AVideo before 29.0 OS Command Injection via execAsync
Original description
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-78 OS Command Injection
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026