---
id: CVE-2025-34438
title: >-
  AVideo versions prior to 20.1 contain an insecure direct object reference
  vulnerability allowing users with upload permissions to modify the rotation
  metadata of any video
summary: >-
  AVideo versions prior to 20.1 contain an insecure direct object reference
  vulnerability allowing users with upload permissions to modify the rotation
  metadata of any video. The endpoint verifies upload capability but fails to
  enforce own…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: wwbn
product: avideo
affected:
  - avideo < 20.0
patched:
  - avideo 20.0
published: '2025-12-17'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34438'
references:
  - url: 'https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/commit/4a53ab2056'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/commit/c2feaf25cb'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/avideo-idor-arbirary-video-rotation'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00283
epssPercentile: 0.18584
ingestedAt: '2026-09-25T23:21:16.945Z'
---

## Overview

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce ownership or management rights for the targeted video.

## Affected

- `avideo < 20.0`

## Remediation

Upgrade past the affected range:

- `avideo 20.0`
