No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue. | |
| Title | marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection | |
| First Time appeared |
Marcopiovanello
Marcopiovanello yt-dlp-web-ui |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:marcopiovanello:yt-dlp-web-ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Marcopiovanello
Marcopiovanello yt-dlp-web-ui |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T02:00:16.308Z
Reserved: 2026-09-17T19:27:07.761Z
Link: CVE-2026-93371
No data.
Status : Received
Published: 2026-09-18T03:16:33.563
Modified: 2026-09-18T03:16:33.563
Link: CVE-2026-93371
No data.
OpenCVE Enrichment
No data.