CVE-2026-33513Path Traversal in Avideo

Severity
7.5HIGHNVD
EPSS
0.2%
top 61.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
Latest updateMar 20
PublishedMar 23

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclosure and code execution of existing PHP content (e.g., `view/about.php`), and it *can* escalate to RCE if an attacker can place or control a PHP f

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDwwbn/avideo26.0
Packagistwwbn/avideo26.0

🔴Vulnerability Details

2
GHSA
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)2026-03-20
OSV
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)2026-03-20

🕵️Threat Intelligence

1
Wiz
CVE-2026-33513 Impact, Exploitability, and Mitigation Steps | Wiz