---
id: CVE-2026-89242
title: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a
  server-side request forgery vulnerability in the _json_decode function that
  fetches remote URLs and local file paths without SSRF validation
summary: >-
  WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a
  server-side request forgery vulnerability in the _json_decode function that
  fetches remote URLs and local file paths without SSRF validation.
  Unauthenticated …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: WWBN
product: AVideo
affected:
  - AVideo <= c3edcc274c389816d434acadac07ee78eaf330c1
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:17:34.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89242'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-wqwf-wmvx-53jh'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-unauthenticated-ssrf-via-login-json-php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-wqwf-wmvx-53jh'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00277
epssPercentile: 0.18008
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T16:09:11.046312Z'
ingestedAt: '2026-09-11T16:45:47.860Z'
---

## Overview

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files or access internal services, with results parsed as login credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
