FixVibe

critical

Critical Command Injection in AVideo via Video Link Embedding

AVideo versions before 12.4 are affected by CVE-2023-25313 / GHSA-pgvh-p3g4-86jw. FixVibe now covers this through safe Composer dependency evidence in GitHub repo scans.

CVE-2023-25313GHSA-pgvh-p3g4-86jwCWE-77CWE-78

AVideo (formerly YouPHPTube) releases before 12.4 have a command-injection vulnerability in the workflow that embeds remote video links [S1][S2]. Public advisories track it as CVE-2023-25313 / GHSA-pgvh-p3g4-86jw and list the affected Composer package as wwbn/avideo [S2].

Impact

If an affected AVideo deployment exposes the vulnerable workflow to an attacker, the issue can cross from media ingestion into operating-system command execution on the host [S1][S2]. Practical risk depends on the deployed version, feature reachability, user permissions around upload/import/link embedding, and any vendor backport.

Covered by FixVibe

FixVibe's GitHub repo scans flag wwbn/avideo versions or constraints below 12.4 in composer.lock and composer.json, showing the file, line, advisory IDs and fixed version.

Remediation

Upgrade AVideo to 12.4 or newer, regenerate composer.lock, rebuild the deployed PHP host or container, and verify the running installation uses the patched Composer dependency [S2]. While the rollout is in progress, limit upload, import, and video-link embedding features to trusted users and review logs if the affected installation was internet-facing.