Vulnerability in Pixeldrain Crawler of Cyberdrop-DL Affects Multiple File Hosts
CVE-2026-54254
5.9MEDIUM
What is CVE-2026-54254?
The Pixeldrain crawler in Cyberdrop-DL versions 8.5.0 to 9.14.0 utilizes substring matching for hostnames instead of verifying if the input host is part of the SUPPORTED_DOMAINS list. This discrepancy allows an attacker to exploit a crafted URL from a lookalike host, leading to the unauthorized transmission of users' Pixeldrain API keys via the Authorization header. This vulnerability can be leveraged through third-party sites, exposing users’ sensitive API details. Version 9.14.0 addresses this issue with enhanced validation mechanisms.
Affected Version(s)
cyberdrop-dl >= 8.5.0, < 9.14.0
