Command Injection Vulnerability in marcopiovanello yt-dlp-web-ui Software
CVE-2026-93371
6.9MEDIUM
What is CVE-2026-93371?
A security issue has been identified in the marcopiovanello yt-dlp-web-ui, specifically in versions up to v4. This vulnerability is characterized by a command injection flaw located in the NewGenericDownload function within the source file server/internal/downloaders/generic.go. An attacker can manipulate specific parameters remotely to execute arbitrary commands. This flaw poses a severe risk as it allows unauthorized access and interactions with the system, potentially leading to significant data breaches or system compromises. A patch has been issued to address this vulnerability, which should be applied immediately to mitigate the risk.
Affected Version(s)
yt-dlp-web-ui v4
