NPM · AUGUST 2026 · EARLY WARNING

AVideo Unauthenticated File Write Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
cve-2026-72748 (npm)
Affected versions
>= 29.0, <= 29.0
Patched version
Not yet available
CVE-2026-72748

An unauthenticated arbitrary file write vulnerability has been reported in AVideo affecting version 29.0. This vulnerability allows remote attackers to write arbitrary content to the server filesystem.

What happened

AVideo reportedly contains a critical vulnerability in the aVideoEncoderChunk.json.php endpoint. This vulnerability allows unauthenticated remote attackers to write up to 4 GB of arbitrary content to the server filesystem. Potential impacts include exhausting disk space causing denial of service, poisoning the video encoding pipeline, or achieving remote code execution. The vulnerability is tracked as CVE-2026-72748 with a CVSS score of 9.1.

The vulnerability was first flagged on 2026-08-11T13:19:05.813000+00:00. It is currently under investigation and has not been reported as exploited in the wild. Users of AVideo version 29.0 are advised to assess their exposure and take immediate action.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cve-2026-72748 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using AVideo version 29.0, you are potentially affected by this vulnerability.

What should I do right now?

Upgrade to the latest version of AVideo and restrict access to the aVideoEncoderChunk.json.php endpoint.

Has an official fix been released?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats