Arbitrary Code Execution Vulnerability in yt-grabber-tui by zheny-creator
CVE-2025-62363
7.8HIGH
What is CVE-2025-62363?
The yt-grabber-tui application, designed for downloading videos via a terminal interface, has a vulnerability that allows an attacker to replace the path to the yt-dlp executable in the configuration file with malicious code. This can occur if the attacker has write permissions to the configuration file or its filesystem. When yt-grabber-tui is used, the malicious code will run with the user's privileges, potentially compromising the user's system. This issue has been addressed in the latest version 1.0-rc.
Affected Version(s)
YtGrabber-TUI < 1.0-rc