Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40908

20
FAUCET Score

WWBN AVideo versions 29.0 and prior contain an information disclosure vulnerability in the git.json.php file, which executes git log commands and returns sensitive output to unauthenticated users. This open-source video platform flaw exposes deployed commit hashes, developer personally identifiable information including names and email addresses, and commit messages that may reference internal systems or security measures. The vulnerability has a CVSS 3.1 score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction, making it trivial to exploit remotely. The impact is limited to confidentiality loss, as attackers cannot modify data or disrupt service availability, but the exposed information enables version fingerprinting against known CVEs and potentially provides reconnaissance data for follow-on attacks. No evidence of active exploitation has been reported, and the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list. However, as of publication there are no known patched versions available, leaving all affected deployments vulnerable. The low EPSS score of 0.00031 and inactive Hot List status suggest minimal current community attention, but organizations running WWBN AVideo should implement access controls to restrict git.json.php or upgrade immediately upon patch availability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 29.0CPE matchmatch criteria
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 7th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-52hf-63q4-r926medium

WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed Version

Apr 14, 2026

References

github.com / WWBN/AVideo/security/advisories/GHSA-52hf-63q4-r926
ExploitVendor Advisory