CVE-2026-41064Patch(wwbn / avideo)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevil[.]com`. Commit 78bccae74634ead68aa6528d631c9ec4fd7aa536 contains an updated fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-25)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 2Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 204-2104-2204-25
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-211
Patch1
2026-04-221
Disclosure1
2026-04-252
Disclosure1Patch1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41064 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leave… https://www.cve.org/CVERecord?id=CVE-2026-41064 ----- Traducción: CVE-2026-41064 WWB… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑41064 for AVideo versions ≤29.0, noting an incomplete patch that may leave a command‑injection flaw in `test.php`. No PoC, exploit code, or evidence of active exploitation is provided.

    0000041
    72 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-41064 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leave… https://www.cve.org/CVERecord?id=CVE-2026-41064

    Post summary

    The advisory highlights that AVideo 29.0 contains an incomplete patch in `test.php` where `escapeshellarg` is partially applied, pointing to CVE-2026-41064.

    00000188
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41064 Remote Code Execution in WWBN AVideo Up To Version 29.0 Via Unsanitized URL Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41064

    Post summary

    The text publishes a brief disclosure of CVE‑2026‑41064, noting a remote code execution flaw in WWBN AVideo (up to 29.0) caused by unsanitized URL validation, but offers no PoC, exploit, or patch details.

    0000054
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2026-41064: AVideo has an incomplete fix for... Half-baked patches are worse than no patches - AVideo's lazy regex `/^http/` bypass and unsanitized curl/file_get_conte... https://zerodaysignal.com/vulnerability/CVE-2026-41064 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet highlights that the CVE‑2026‑41064 patch is incomplete, pointing out a regex bypass and unsanitized input, implying a lingering security risk.

    0000079
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more