{"id":"GHSA-9j26-99jh-v26q","summary":"WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php","details":"## Impact\n\nAn unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the `base64Url` GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration secrets, internal keys, credentials), and service disruption.\n\n## Root Cause\n\nThe `base64Url` parameter is Base64-decoded and then interpolated directly into a double-quoted `ffmpeg` shell command without proper shell escaping. The upstream validation uses `FILTER_VALIDATE_URL`, which validates URL syntax but does not prevent shell metacharacters / command substitution sequences from being interpreted by the shell.\n\n## Affected Components\n\n* `objects/getImage.php`\n* `objects/security.php`\n* Execution path via async command execution helper (`shell_exec`/`nohup`)\n\n## Patches\n\nApply strict shell argument escaping (e.g., `escapeshellarg()`) to all user-supplied values before building any shell command, and avoid double-quoted interpolation of untrusted input. Prefer safer process execution patterns where possible.\n\n## Workarounds\n\n* Restrict access to `objects/getImage.php` at the web server / reverse proxy layer (IP allowlist, auth, or disable endpoint if not needed).\n* Apply WAF rules to block suspicious patterns and limit exposure until a patch is deployed.\n\n## Resources\n\n* Report: \"Unauthenticated OS Command Injection in AVideo-Encoder\"","aliases":["CVE-2026-29058"],"modified":"2026-03-06T22:01:31.529367Z","published":"2026-03-03T20:02:40Z","database_specific":{"nvd_published_at":"2026-03-06T07:16:02Z","cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-03-03T20:02:40Z"},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-9j26-99jh-v26q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29058"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo-Encoder"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-9j26-99jh-v26q/GHSA-9j26-99jh-v26q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}