CVE-2026-33319 PUBLISHED CVSS 5.900000095367432 MEDIUM

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can influence the LinkedIn API response (via MITM, compromised OAuth token, or API compromise), they can inject arbitrary OS commands that execute as the web server user. Version 26.0 contains a fix for the issue.

EPSS 0.03% · 7.3th percentile

Risk Scores

CVSS v3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.03%
7.3th percentile

Affected Products

VendorProductVersions
wwbnavideo0, 0, 0
WWBNAVideo< 26.0, < 26.0, < 26.0
wwbnavideo0, 0, 0

Timeline

References

Open in Interactive Console →