Cross Site Scripting Vulnerability in aandrew-me ytDownloader
CVE-2026-6218
Key Information:
- Vendor
Aandrew-me
- Status
- Vendor
- CVE Published:
- 13 April 2026
Badges
What is CVE-2026-6218?
A cross site scripting vulnerability exists in the 'createTextNode' function of the Error Details Panel in the aandrew-me ytDownloader, affecting versions up to 3.20.2. This flaw enables remote attackers to execute arbitrary scripts that may compromise user data or session information. The weakness can be exploited without user interaction, raising significant security concerns. Users and administrators are encouraged to apply necessary updates and review their security posture to mitigate potential risks associated with this vulnerability.
Affected Version(s)
ytDownloader 3.20.0
ytDownloader 3.20.1
ytDownloader 3.20.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
