
CVE-2026-39370 WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with comm… https://www.cve.org/CVERecord?id=CVE-2026-39370
Post summary
The tweet announces CVE-2026-39370 as a vulnerability in WWBN AVideo allowing attacker-controlled downloadURL values, without providing PoC, exploit, or patch details.
