CVE-2026-41304Disclosure(wwbn / avideo)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command executed via `exec()`, allowing command injection. An attacker can inject arbitrary shell commands by breaking out of the intended URL context using shell metacharacters (e.g., `;`). This leads to Remote Code Execution (RCE) on the server. Commit 473c609fc2defdea8b937b00e86ce88eba1f15bb contains a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-25)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-22: 1Mentions · 2026-04-25: 3Technical Details · 2026-04-22: 1Technical Details · 2026-04-25: 304-2204-25
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-253
Disclosure2General1
Full discourse4 posts
  • z3n@zench4n
    General

    Traditional CVEs like CVE-2026-41304 in WWBN AVideo or PJSIP memory issues remain the building blocks. In an agentic ecosystem, an LLM might inadvertently trigger these flaws via tool calls, turning a simple prompt into a remote code execution event.

    Post summary

    The snippet references existing CVEs and notes that large language models could inadvertently trigger memory‑related remote code execution via tool calls, but it offers no PoC, exploit, patch, or reports of real‑world exploitation.

    1000037
    1.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41304 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using … https://www.cve.org/CVERecord?id=CVE-2026-41304 ----- Traducción: CVE-2026-41304 WWB… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-41304 in WWBN AVideo, noting a shell-command construction flaw in the CloneSite plugin for older releases.

    0000047
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41304 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using … https://www.cve.org/CVERecord?id=CVE-2026-41304

    Post summary

    WWBN AVideo’s CloneSite plugin in versions 29.0 and earlier allows shell command construction, posing a potential code‑execution risk; the CVE is documented but no PoC, exploit, or patch details are provided.

    00000169
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41304 Command Injection in WWBN AVideo CloneSite Plugin Versions 29.0 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41304

    Post summary

    A command injection vulnerability affecting WWBN AVideo CloneSite Plugin versions 29.0 and below has been disclosed, but no PoC, exploit, patch, or active usage evidence is provided.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more