
🚨 UPDATED ALERT: CVE-2026-33501 in AVideo – Confirmed Vulnerability (Official Patch Already Released) 🚨 WARNING FOR ANYONE USING AVideo (or who knows someone who does): The world’s most popular open-source video platform has a serious unauthorized permission information disclosure vulnerability. What we know now (official sources – NVD + GitHub): • CVE-2026-33501 • Affects ALL versions up to and including 26.0 • Vulnerable endpoint: /plugin/Permissions/View/Users_groups_permissions/list.json.php • Anyone on the internet can download the complete user groups × plugins permission mapping without any login • CVSS 5.3 (Medium) – extremely easy to exploit (literally a single curl command) Fofa searches (reports from the Chinese security community) show more than 100,000 publicly exposed instances using the simple query "AVideo" or title="AVideo". Good news: The official team has already published the patches! ✅ Fix commits: • https://github.com/WWBN/AVideo/commit/dc3c825734628bb32550d0daa125f05bacb6829c • https://github.com/WWBN/AVideo/commit/b583acdc9a9d1eab461543caa363e1a104fb4516 Official GitHub Security Advisory: https://github.com/WWBN/AVideo/security/advisories/GHSA-96qp-8cmq-jvq8 WHAT TO DO RIGHT NOW: 1. Update immediately to the latest code (apply the commits) 2. If you can’t update yet → block external access to the entire /plugin/Permissions/ directory #AVideo #CVE2026-33501 #CyberSecurity #Vulnerability #InfoSec #PatchNow #OpenSourceSecurity
Post summary
AVideo’s CVE-2026-33501 is an information‑disclosure flaw that can be trivially exploited; official patches are available and users are urged to update immediately.



