CVE-2026-33237Disclosure(wwbn / avideo)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpoints that were recently patched for SSRF (GHSA-9x67-f2v7-63rw, GHSA-h39h-7cvg-q7j6), the Scheduler's callback URL is never passed through `isSSRFSafeURL()`, which blocks requests to RFC-1918 private addresses, loopback, and cloud metadata endpoints. An admin can configure a scheduled task with an internal network `callbackURL` to perform SSRF against cloud infrastructure metadata services or internal APIs not otherwise reachable from the internet. Version 26.0 contains a patch for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-24: 103-2103-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-241
General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🔴 WWBN AVideo, SSRF, #CVE-2026-33237 (Critical) https://dailycve.com/wwbn-avideo-ssrf-cve-2026-33237-critical/

    Post summary

    A brief alert noting the discovery of a critical SSRF vulnerability, CVE-2026-33237, in WWBN AVideo.

    0000038
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33237 WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_conten… https://www.cve.org/CVERecord?id=CVE-2026-33237

    Post summary

    The text announces CVE‑2026‑33237 affecting the Scheduler plugin in WWBN AVideo before version 26.0, with no additional details on exploitation or mitigation.

    0000074
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33237 - AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation Intel Report: https://ift.tt/deHP6iX

    Post summary

    A new SSRF vulnerability (CVE-2026-33237) has been identified in AVideo's Scheduler Plugin due to missing callbackURL validation, with an intel report provided.

    0000042
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more