PT-2026-92086 · Avideo · Avideo

·

CVE-2026-91967

·

Published

2026-09-15

·

Updated

2026-09-17

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.1
Description A blind server-side request forgery exists in the getHeaderContentTypeFromURL() function, which performs get headers() calls that are only protected by format validation. Authenticated users with canUpload permission can store malicious URLs as video links. This triggers the vulnerable function whenever a video watch page is rendered, allowing the probing of internal hosts through timing-based detection and content-type oracles (a method of inferring information based on the server's response headers).
Recommendations Update to a version newer than 29.0. As a temporary mitigation, restrict the canUpload permission to trusted users only.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91967
GHSA-VJGR-5X63-CQ96

Affected Products

Avideo