Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
IINA < 1.4.3 Command Execution via iina://open URL Scheme
Vulnerability Description
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command execution as the current macOS user upon approval of the browser protocol prompt without requiring a valid media file.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
参数注入或修改
Vulnerability Title
IINA 参数注入漏洞
Vulnerability Description
IINA是IINA开源的一款基于mpv的现代macOS视频播放器。 IINA 1.4.3之前版本存在参数注入漏洞,该漏洞源于通过iina://open自定义URL方案处理程序未验证mpv_options/input-commands参数,可能导致远程攻击者通过浏览器提供特制URL,在用户批准浏览器协议提示后,将未验证参数传递给mpv运行时,从而在macOS用户权限下执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A