Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking

A critical vulnerability in AVideo, a widely used open-source video hosting and streaming platform. Tracked as CVE-2026-29058, this zero-click flaw carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating system commands on the targeted server. Discovered by security researcher Arkmarta, the vulnerability specifically affects AVideo version 6.0. It has been officially patched […]

The post Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: