---
id: CVE-2025-34437
title: >-
  AVideo versions prior to 20.1 permit any authenticated user to upload comment
  images to videos owned by other users
summary: >-
  AVideo versions prior to 20.1 permit any authenticated user to upload comment
  images to videos owned by other users. The endpoint validates authentication
  but omits ownership checks, allowing attackers to perform unauthorized uploads
  to …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-639
vendor: wwbn
product: avideo
affected:
  - avideo < 20.0
patched:
  - avideo 20.0
published: '2025-12-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34437'
references:
  - url: 'https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/commit/4a53ab2056'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/commit/d411f91805'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/avideo-idor-arbitrary-comment-image-upload
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00395
epssPercentile: 0.3121
ingestedAt: '2026-09-30T23:29:32.497Z'
---

## Overview

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.

## Affected

- `avideo < 20.0`

## Remediation

Upgrade past the affected range:

- `avideo 20.0`
