CVE-2026-64625
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.35%
- 28th pct
- KEV
- No
- Class
- oss containerizable
- CWE-78
Description
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.
References
Status: profiled · ingested 2026-07-23T18:00:18.000Z