CVE-2026-40908

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enabling version fingerprinting against known CVEs), developer names and email addresses (PII), and commit messages which may contain references to internal systems or security fixes. As of time of publication, no known patched versions are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

23 Apr 2026, 19:09

Type Values Removed Values Added
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
First Time Wwbn
Wwbn avideo
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-52hf-63q4-r926 - () https://github.com/WWBN/AVideo/security/advisories/GHSA-52hf-63q4-r926 - Exploit, Vendor Advisory

22 Apr 2026, 14:17

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-52hf-63q4-r926 - () https://github.com/WWBN/AVideo/security/advisories/GHSA-52hf-63q4-r926 -

21 Apr 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 20:17

Updated : 2026-06-17 10:45


NVD link : CVE-2026-40908

Mitre link : CVE-2026-40908

CVE.ORG link : CVE-2026-40908


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor