CVE-2026-85160: AVideo through c91b5975d CSRF and Path Traversal via stopLive.php

Published Sep 3, 2026
·
Updated

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.

Affected Software

1 affected component
AVideo=c91b5975d

Event History

Sep 3, 2026
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

AVideo instances are exposed when an administrator can be induced to visit an attacker-controlled malicious page. The attack is delivered through a crafted image request and does not require the attacker to authenticate.

2

What is the likely impact if exploitation succeeds?

The attacker can trigger recursive deletion of directories through the vulnerable stopLive.php endpoint. The provided example uses a traversal payload to delete the videos directory, affecting integrity and availability.

3

How can I determine whether my installation is affected?

The affected scope is AVideo through commit c91b5975d. Review whether your deployed code includes stopLive.php with missing token validation and direct concatenation of the key parameter into a filesystem path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203