CVE-2026-64625
AVideo before version 29.0 has a command injection flaw in its Live plugin. The flaw lets attackers run arbitrary OS commands through the on_publish.php endpoint, bypassing shell escaping. This can lead to full server compromise.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
AVideo installations using the Live plugin on versions prior to 29.0, especially those exposing the on_publish.php endpoint.
Real-world impact
An attacker could execute any command on the server, potentially taking full control, stealing data, installing malware, or disrupting services.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability is exploitable remotely with no authentication, has high impact on confidentiality, integrity, and availability, and requires minimal effort.
What to do about it
- ›Disable the Live plugin or remove the on_publish.php endpoint until a patch is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 20, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.