#VU125510 Path traversal in AVideo - CVE-2026-39369
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in objects/aVideoEncoderReceiveImage.json.php when processing a crafted same-origin /videos/... URL through downloadURL_gifimage. A remote user can supply a specially crafted downloadURL_gifimage value to disclose sensitive information.
The issue can expose server-local files by leaving fetched non-image content accessible through a public GIF media URL.