A critical, zero-click unauthenticated OS command injection vulnerability was disclosed in the open-source video hosting/streaming platform AVideo, tracked as CVE-2026-29058. The flaw affects versions prior to 7.0 (including 6.0) and allows remote attackers to execute arbitrary operating system commands on the server without user interaction or prior privileges, creating a path to full server compromise, data exfiltration (e.g., configuration secrets, internal keys, credentials), and service disruption.
The issue stems from objects/getImage.php, where attacker-controlled input in the base64Url GET parameter is Base64-decoded and incorporated into a double-quoted ffmpeg shell command without proper escaping/neutralization of shell metacharacters and command substitution (CWE-78). The vulnerability was reported by security researcher Arkmarta, and remediation is available by upgrading to AVideo 7.0 or later, which includes the official patch.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described the flaw as a critical zero-click issue affecting pre-7.0 AVideo deployments, including version 6.0, and explained that exploitation could enable server compromise, credential theft, service disruption, and live stream hijacking. Mitigation guidance included upgrading, restricting access to the endpoint, deploying WAF rules, or disabling the image retrieval component if unnecessary.
The vulnerability was addressed in AVideo version 7.0 and later. The fix reportedly added safer shell argument handling, such as strict escaping, to prevent command injection via the vulnerable endpoint.
Security researcher Arkmarta identified CVE-2026-29058, an unauthenticated OS command injection flaw in AVideo/AVideo-Encoder caused by unsafe handling of the base64Url parameter in objects/getImage.php. The vulnerability allows remote attackers to inject shell commands through an ffmpeg invocation and potentially fully compromise the server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.