Path traversal in AVideo - CVE-2026-39369
Published: April 8, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in objects/aVideoEncoderReceiveImage.json.php when processing a crafted same-origin /videos/... URL through downloadURL_gifimage. A remote user can supply a specially crafted downloadURL_gifimage value to disclose sensitive information.
The issue can expose server-local files by leaving fetched non-image content accessible through a public GIF media URL.