SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89148

MEDIUM · CVSS 5.4 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

AVideo contains an open redirect vulnerability in the playlist sorting functionality, allowing remote unauthenticated attackers to manipulate the sort parameter and redirect users to malicious sites. This could lead to phishing attacks targeting users with management access to playlists, as their browsers may be redirected from legitimate AVideo URLs. Organizations using AVideo, particularly those with user management capabilities, should prioritize addressing this vulnerability due to the potential for exploitation and the absence of a patched version.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-89148
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%

Original NVD Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request includes the sort parameter the script issues a Location header set to the unvalidated $_SERVER['HTTP_REFERER'] value without calling isSafeRedirectURL(). A remote unauthenticated attacker can therefore induce a logged-in user who can manage the targeted playlist to submit a cross-origin POST with a crafted Referer, causing the victim's playlist to be reordered and the victim's browser to be redirected from a trusted AVideo URL to an attacker-controlled site for phishing. No patched version is available.