PT-2026-95225 · Marcopiovanello · Yt-Dlp-Web-Ui
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
marcopiovanello yt-dlp-web-ui versions prior to v5
Description
Remote command injection is possible through the manipulation of the
params argument within the NewGenericDownload() function located in the server/internal/downloaders/generic.go file.Recommendations
Apply patch c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897 to versions prior to v5.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yt-Dlp-Web-Ui