CVE-2026-83595: Avideo Csrf Bypass Same Domain Check

State-changing API action is executed while same-domain checks are explicitly bypassed without validating the HTTP request method or request origin, leading to CSRF.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-83595-avideo-csrf-bypass-same-domain-check --engine opengrep

Description

State-changing API action is executed while same-domain checks are explicitly bypassed without validating the HTTP request method or request origin, leading to CSRF.