PKSA-jrf5-73b5-1wm8 Security Advisory
-
[HIGH] WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
PKSA-jrf5-73b5-1wm8 CVE-2026-39369 GHSA-f4f9-627c-jh33
Affected package: wwbn/avideo
Affected version: <=26.0
Reported by:
GitHub