Vulnerability in Pixeldrain Crawler of Cyberdrop-DL Affects Multiple File Hosts
CVE-2026-54254

5.9MEDIUM

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-54254?

The Pixeldrain crawler in Cyberdrop-DL versions 8.5.0 to 9.14.0 utilizes substring matching for hostnames instead of verifying if the input host is part of the SUPPORTED_DOMAINS list. This discrepancy allows an attacker to exploit a crafted URL from a lookalike host, leading to the unauthorized transmission of users' Pixeldrain API keys via the Authorization header. This vulnerability can be leveraged through third-party sites, exposing users’ sensitive API details. Version 9.14.0 addresses this issue with enhanced validation mechanisms.

Affected Version(s)

cyberdrop-dl >= 8.5.0, < 9.14.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.