#VU125450 OS Command Injection in AVideo - CVE-2026-33319
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to execute arbitrary OS commands.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the SocialMediaPublisher plugin uploadVideoToLinkedIn() method when processing a LinkedIn API upload URL in a shell command. A remote privileged user can influence the LinkedIn API response to inject shell metacharacters and execute arbitrary OS commands.
Exploitation requires control over the LinkedIn API response, such as through a compromised OAuth token, API compromise, or a man-in-the-middle condition affecting that trusted response.