<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical Zero-Click Flaw in AVideo Platform Enables Complete Server Takeover

Critical zero-click flaw CVE-2026-29058 in AVideo 6.0 lets attackers execute commands. Upgrade to 7.0 to secure your platform.
Content Team

Security researcher Arkmarta discovered a critical zero-click vulnerability (CVE-2026-29058) in AVideo, a popular open-source video streaming platform. The flaw affects version 6.0 and allows attackers to execute arbitrary commands without authentication through the objects/getImage.php component.

The vulnerability occurs when AVideo processes base64Url parameters in network requests. While the platform attempts basic URL validation, it fails to neutralize dangerous shell characters before executing ffmpeg commands. This oversight lets attackers inject malicious code, steal credentials, and hijack live streams.

Administrators should immediately upgrade to version 7.0, which fixes the issue with proper shell argument escaping. Those unable to upgrade can restrict access to the vulnerable endpoint or deploy WAF rules blocking suspicious Base64 patterns.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo