CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-64625

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
0.35%
28th pct
KEV
No
Class
oss containerizable
CWE-78

Description

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.

References

Status: profiled · ingested 2026-07-23T18:00:18.000Z