{"id":11197,"date":"2026-03-08T10:03:37","date_gmt":"2026-03-08T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/08\/critical-zero-click-command-injection-in-avideo-platform-allows-stream-hijacking\/"},"modified":"2026-03-08T10:03:37","modified_gmt":"2026-03-08T10:03:37","slug":"critical-zero-click-command-injection-in-avideo-platform-allows-stream-hijacking","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/08\/critical-zero-click-command-injection-in-avideo-platform-allows-stream-hijacking\/","title":{"rendered":"Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking"},"content":{"rendered":"<p>    Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability in AVideo, a widely used <a href=\"https:\/\/cybersecuritynews.com\/proxyware-malware-mimic-as-youtube\/\" target=\"_blank\" rel=\"noreferrer noopener\">open-source video hosting and streaming platform.<\/a> Tracked as CVE-2026-29058, this <a href=\"https:\/\/cybersecuritynews.com\/zero-click-flaw-with-apple-mail\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-click flaw<\/a> carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating system commands on the targeted server.<\/p>\n<p>Discovered by security researcher Arkmarta, the vulnerability specifically affects AVideo version 6.0. It has been officially patched in version 7.0 and later releases.<\/p>\n<p>Classified under <a href=\"https:\/\/cybersecuritynews.com\/vmware-vcenter-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CWE-78 for the improper neutralization of special elements in an OS command<\/a>, this network-based attack requires no system privileges or user interaction.<\/p>\n<p>If successfully exploited, attackers could achieve full server compromise, steal sensitive configuration secrets, and completely <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploited-xss-vulnerability-framework\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack live video streams.<\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"h-avideo-platform-vulnerability\"><strong>AVideo Platform Vulnerability<\/strong><\/h2>\n<p>The root cause of this severe vulnerability lies within the\u00a0objects\/getImage.php\u00a0component of the AVideo platform.<\/p>\n<p>The issue occurs when the application processes network requests that contain a\u00a0base64Url\u00a0parameter.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/steganography-attacks-xworm-in-pngs\/\" target=\"_blank\" rel=\"noreferrer noopener\">platform Base64-decodes this user-supplied input<\/a> and interpolates it directly into a double-quoted\u00a0ffmpeg\u00a0shell command.<\/p>\n<p>While the software attempts to validate the input using standard URL filters, this function only checks for basic URL syntax.<\/p>\n<p>It entirely fails to neutralize <a href=\"https:\/\/cybersecuritynews.com\/cacti-command-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">dangerous shell metacharacters or command substitution<\/a> sequences.<\/p>\n<p>Because the application does not properly escape this untrusted data before executing the command, remote attackers can easily append malicious instructions.<\/p>\n<p>This allows<a href=\"https:\/\/cybersecuritynews.com\/mcp-servers-can-be-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\"> unauthorized users to run arbitrary code<\/a>, exfiltrate internal credentials, or intentionally disrupt the server\u2019s streaming capabilities.<\/p>\n<p><a href=\"https:\/\/github.com\/WWBN\/AVideo-Encoder\/security\/advisories\/GHSA-9j26-99jh-v26q\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to the advisory on GitHub<\/a>, administrators running AVideo-Encoder version 6.0 should upgrade to version 7.0 or later to secure their environments.<\/p>\n<p>The official patched release resolves the issue by applying strict shell argument escaping, utilizing functions like\u00a0escapeshellarg().<\/p>\n<p>This crucial fix ensures that all user-supplied input is properly sanitized before it ever interacts with the underlying command line, effectively preventing attackers from breaking out of the intended command structure.<\/p>\n<p>If an immediate software upgrade is not feasible, security teams must deploy temporary workarounds to protect their streaming infrastructure.<\/p>\n<p>Administrators should strongly restrict access to the vulnerable\u00a0objects\/getImage.php\u00a0endpoint at the <a href=\"https:\/\/cybersecuritynews.com\/zardoor-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">web server or reverse proxy layer using strict IP allowlisting.<\/a><\/p>\n<p>Additionally, organizations should apply <a href=\"https:\/\/cybersecuritynews.com\/best-web-application-firewall-waf\/\" target=\"_blank\" rel=\"noreferrer noopener\">Web Application Firewall (WAF) rules<\/a> designed to inspect and actively block suspicious Base64-encoded shell command patterns.<\/p>\n<p>As a final protective measure, administrators can turn off the image retrieval component entirely if it is not required for the platform\u2019s daily operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/avideo-platform-vulnerability\/\">Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/avideo-platform-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking A critical vulnerability in AVideo, a widely used open-source video hosting and streaming platform. Tracked as CVE-2026-29058, this zero-click flaw carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating system commands on the targeted server. Discovered by security researcher Arkmarta, the vulnerability [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11197","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11197"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11197"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11197\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}