GHSA-9j26-99jh-v26q · Severity: critical · Ecosystem: composer — WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration secrets, internal keys, credentials), and service disruption. This issue has been patched in version 7.0.
Conclusion & alert: CVE-2026-29058 is rated High Risk (74.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 51.78%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-13 | 50.86% | 51.78% | +0.92% |
| 2 | 2026-04-07 | 42.99% | 50.86% | +7.87% |
| 3 | 2026-03-28 | — | 42.99% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-9j26-99jh-v26q · Severity: critical · Ecosystem: composer — WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| wwbn | avideo-encoder | < 7.0 | cpe:2.3:a:wwbn:avideo-encoder:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/WWBN/AVideo-Encoder/security/advisories/GHSA-9j26-99jh-v26q | Mitigation Vendor Advisory |