CVE-2026-33319Disclosure(wwbn / avideo)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can influence the LinkedIn API response (via MITM, compromised OAuth token, or API compromise), they can inject arbitrary OS commands that execute as the web server user. Version 26.0 contains a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-22); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-22: 2Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 103-2203-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-222
Disclosure2
2026-03-231
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33319 WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell comman… https://www.cve.org/CVERecord?id=CVE-2026-33319

    Post summary

    The post identifies CVE-2026-33319 as a command injection flaw in WWBN AVideo’s SocialMediaPublisher plugin before version 26.0.

    00000116
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33319 Command Injection Vulnerability in WWBN AVideo Social Media Publisher Plugin Pre-26.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33319

    Post summary

    CVE‑2026‑33319 describes a command injection flaw in the WWBN AVideo Social Media Publisher Plugin pre‑26.0, with additional details available via the provided link.

    0000033
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33319 - AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command Intel Report: https://ift.tt/6cBE5ui

    Post summary

    CVE-2026-33319 is a command‑injection vulnerability in AVideo's LinkedIn video upload shell, announced with technical details but without any PoC, exploit code, or patch information.

    0000033
    292 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more