CVE-2026-41058: AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo
WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite deleteDump parameter does not apply path traversal filtering, allowing unlink() of arbitrary files via ../../ sequences in the GET parameter. Commit 3c729717c26f160014a5c86b0b6accdbd613e7b2 contains an updated fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41058?
CVE-2026-41058 has a high severity rating due to its potential for arbitrary file deletion.
How do I fix CVE-2026-41058?
To fix CVE-2026-41058, you should upgrade AVideo to a version higher than 29.0 that implements complete path traversal filtering.
What software is affected by CVE-2026-41058?
The affected software for CVE-2026-41058 is WWBN AVideo version 29.0 and below.
What does CVE-2026-41058 vulnerability entail?
CVE-2026-41058 involves an incomplete fix for path traversal vulnerability, allowing unauthorized file deletions via the 'deleteDump' parameter.
Is there a workaround for CVE-2026-41058?
There is no documented workaround for CVE-2026-41058; upgrading the software is necessary to address the issue.