GHSA-pq8p-wc4f-vg7j: WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
The incomplete fix for AVideo’s test.php adds escapeshellarg for wget but leaves the file_get_contents and curl code paths unsanitized, and the URL validation regex /^http/ accepts strings like httpevil.com.
References
Code Behaviors & Features
Detect and mitigate GHSA-pq8p-wc4f-vg7j with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →