
CVE-2026-40908 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as… https://www.cve.org/CVERecord?id=CVE-2026-40908
Post summary
The post discloses that versions 29.0 and earlier of WWBN AVideo expose a command execution vector via `git.json.php`—it runs `git log -1` and returns the output, but no PoC, exploit, patch, or active exploitation details are provided.

