GHSA-9x67-f2v7-63rw: AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
highvulnerability
security
Summary
AVideo's LiveLinks proxy endpoint validates URLs to block requests to internal networks, but only checks the initial URL. When a URL redirects (sends back a `Location` header pointing elsewhere), the code follows the redirect without re-validating the new target, letting attackers reach internal services like cloud metadata or private networks. The endpoint is also completely unauthenticated, so anyone can access it.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
March 17, 2026
Classification
Attack SophisticationModerate
Affected Packages
wwbn/avideo@<= 25.0
Original source: https://github.com/advisories/GHSA-9x67-f2v7-63rw
First tracked: March 17, 2026 at 04:55 PM
Classified by LLM (prompt v3) · confidence: 95%