Command Injection Vulnerability in aandrew-me ytDownloader by aandrew-me
CVE-2026-6219
Key Information:
- Vendor
Aandrew-me
- Status
- Vendor
- CVE Published:
- 13 April 2026
Badges
What is CVE-2026-6219?
A command injection vulnerability exists in aandrew-me ytDownloader versions up to 3.20.2, specifically affecting the child_process.exec function in src/compressor.js. This vulnerability allows malicious users to execute arbitrary commands on the local system. Although the attack must be executed locally, the potential for exploitation is significant. The vendor has been informed of this issue prior to public disclosure, and users are advised to update to mitigate risks associated with this vulnerability.
Affected Version(s)
ytDownloader 3.20.0
ytDownloader 3.20.1
ytDownloader 3.20.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
