AVideo versions before 24.0 contain a server-side request forgery (SSRF) vulnerability in the isSSRFSafeURL function. The function fails to properly extract embedded IPv4 addresses from IPv6 transition address formats including NAT64, 6to4, and Teredo. Unauthenticated attackers can exploit the LiveLinks proxy endpoint to bypass SSRF protections. By encoding private IPv4 targets within IPv6 transition address formats, attackers can reach internal services and cloud metadata endpoints. No authentication is required to exploit this vulnerability. The issue is patched in AVideo version 24.0. Cloud-hosted instances are particularly at risk due to potential exposure of cloud metadata services such as AWS IMDSv1. This represents a significant risk for organizations running AVideo in cloud or internal network environments.