在 marcopiovanello yt-dlp-web-ui v4 及更早版本中发现了一个安全漏洞。该问题影响文件 server/internal/downloaders/generic.go 中的 NewGenericDownload 函数。对该函数的参数 params 进行不当操作会导致命令注入漏洞。攻击者可以远程发起此攻击。该漏洞的利用方法已公开披露,并可能已被利用。修复补丁的提交哈希为 c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897。建议应用该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| marcopiovanello | yt-dlp-web-ui | v4 |
cpe:2.3:a:marcopiovanello:yt-dlp-web-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet