AVideo (formerly YouPHPTube) releases before 12.4 have a command-injection vulnerability in the workflow that embeds remote video links [S1][S2]. Public advisories track it as CVE-2023-25313 / GHSA-pgvh-p3g4-86jw and list the affected Composer package as wwbn/avideo [S2].
Impact
If an affected AVideo deployment exposes the vulnerable workflow to an attacker, the issue can cross from media ingestion into operating-system command execution on the host [S1][S2]. Practical risk depends on the deployed version, feature reachability, user permissions around upload/import/link embedding, and any vendor backport.
Covered by FixVibe
FixVibe's GitHub repo scans flag wwbn/avideo versions or constraints below 12.4 in composer.lock and composer.json, showing the file, line, advisory IDs and fixed version.
Remediation
Upgrade AVideo to 12.4 or newer, regenerate composer.lock, rebuild the deployed PHP host or container, and verify the running installation uses the patched Composer dependency [S2]. While the rollout is in progress, limit upload, import, and video-link embedding features to trusted users and review logs if the affected installation was internet-facing.
