Command Injection Affecting wwbn/avideo package, versions >=0.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
2.16% (81st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Command Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-WWBNAVIDEO-17660434
  • published27 Jun 2026
  • disclosed23 Jun 2026
  • creditanir0y

Introduced: 23 Jun 2026

CVE-2026-55173  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

wwbn/avideo is an Audio and Video Platform or simply "A Video Platform".

Affected versions of this package are vulnerable to Command Injection via the sanitizeFFmpegCommand process. An attacker can execute arbitrary operating system commands by injecting a single & character into the command string, which is not properly sanitized and is interpreted as a command separator by the shell.

CVSS Base Scores

version 4.0
version 3.1