WWBN AVideo Path Traversal Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- wwbn-avideo (npm)
- Affected versions
- >= 29.0, <= 29.0 or >= 26.0, <= 26.0 or >= 25.0, <= 25.0 or >= 24.0, <= 24.0 or >= 22.0, <= 22.0 or >= 21.0, <= 21.0 or >= 18.0, <= 18.0 or >= 14.3.1, <= 14.3.1 or >= 14.3, <= 14.3 or >= 12.4, <= 12.4 or >= 11.6, <= 11.6 or >= 11.5, <= 11.5 or >= 11.1.1, <= 11.1.1 or >= 11.1, <= 11.1 or >= 11, <= 11 or >= 10.8, <= 10.8 or >= 8.9.1, <= 8.9.1 or >= 8.9, <= 8.9 or >= 8.7, <= 8.7 or >= 8.6, <= 8.6 or >= 8.5, <= 8.5 or >= 8.1, <= 8.1 or >= 7.8, <= 7.8 or >= 7.7, <= 7.7 or >= 7.6, <= 7.6 or >= 7.4, <= 7.4 or >= 7.3, <= 7.3 or >= 7.2, <= 7.2 or >= 4.0, <= 4.0 or >= 3.4, <= 3.4 or >= 2.7, <= 2.7 or >= 2.2, <= 2.2
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in WWBN AVideo that allows unauthenticated attackers to write files to arbitrary locations. Users of affected versions should assess their exposure.
What happened
WWBN AVideo reportedly contains a path traversal vulnerability in notify.ffmpeg.json.php. This vulnerability allows unauthenticated attackers to write files to arbitrary locations by replaying previously issued ciphertext as a notifyCode token. The vulnerability is under investigation and has not been exploited in the wild as of the latest reports. Users of affected versions should review their systems for any unauthorized files written to the application root and subdirectories.
The affected versions of wwbn-avideo (npm) span a wide range, from version 29.0 down to 2.2 inclusive. The vulnerability impacts all versions within these ranges. No official fix has been published yet, and users are advised to monitor the provided sources for updates.
What to do about it
- Monitor the provided sources for updates on a patch release.
- Review your system for any unauthorized files written to the application root and subdirectories.
- If a patch becomes available, upgrade to the latest version of wwbn-avideo.
- Continue to monitor the situation as more information becomes available.
How 0Day would have caught this
wwbn-avideo is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using wwbn-avideo (npm) in the version ranges >= 29.0, <= 29.0 or >= 26.0, <= 26.0 or >= 25.0, <= 25.0 or >= 24.0, <= 24.0 or >= 22.0, <= 22.0 or >= 21.0, <= 21.0 or >= 18.0, <= 18.0 or >= 14.3.1, <= 14.3.1 or >= 14.3, <= 14.3 or >= 12.4, <= 12.4 or >= 11.6, <= 11.6 or >= 11.5, <= 11.5 or >= 11.1.1, <= 11.1.1 or >= 11.1, <= 11.1 or >= 11, <= 11 or >= 10.8, <= 10.8 or >= 8.9.1, <= 8.9.1 or >= 8.9, <= 8.9 or >= 8.7, <= 8.7 or >= 8.6, <= 8.6 or >= 8.5, <= 8.5 or >= 8.1, <= 8.1 or >= 7.8, <= 7.8 or >= 7.7, <= 7.7 or >= 7.6, <= 7.6 or >= 7.4, <= 7.4 or >= 7.3, <= 7.3 or >= 7.2, <= 7.2 or >= 4.0, <= 4.0 or >= 3.4, <= 3.4 or >= 2.7, <= 2.7 or >= 2.2, <= 2.2.
What should I do right now?
Monitor the provided sources for updates on a patch release. Review your system for any unauthorized files written to the application root and subdirectories. If a patch becomes available, upgrade to the latest version of wwbn-avideo.
Is there an official fix available?
No official fix has been published yet. Continue to monitor the provided sources for updates.