Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-33764

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Mar 27, 2026
Vendor unknown

Description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` parameter without validating that the AI response belongs to the specified video. An authenticated user with AI permissions can reference any AI response ID โ€” including those generated for other users' private videos โ€” and apply the stolen AI-generated content (titles, descriptions, keywords, summaries, or full transcriptions) to their own video, effectively exfiltrating the information. Commit aa2c46a806960a0006105df47765913394eec142 contains a patch.

References