Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f786-7wmv-h56x

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.

EPSS

Процентиль: 18%
0.00258
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.1
nvd
13 дней назад

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.

EPSS

Процентиль: 18%
0.00258
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-639