Vulnerability Description
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and extract them from the itunes:email and itunes:author RSS elements, enabling account takeover attempts and phishing campaigns.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-w44x-v4c8-86f6
- https://www.vulncheck.com/advisories/avideo-feed-index-php-exposure-of-channel-o
FAQ
What is CVE-2026-56380?
CVE-2026-56380 is a vulnerability with a CVSS score of 5.3 (MEDIUM). AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public ch...
How severe is CVE-2026-56380?
CVE-2026-56380 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56380?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.