CVE-2026-33512: AVideo has an unauthenticated decrypt oracle leaking any ciphertext
(updated )
The API plugin exposes a decryptString action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., view/url2Embed.json.php), so any user can recover protected tokens/metadata. Severity: High.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33512 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →