Impact
The vulnerability exists in the stream function of public/stream.php and is triggered by manipulating the url parameter. Exploitation allows an attacker to cause the server to send arbitrary HTTP or HTTPS requests to any destination, potentially exposing internal resources or enabling data exfiltration. The weakness is a classic SSRF flaw, classified as CWE‑918.
Affected Systems
The affected product is athlon1600 youtube‑downloader; releases up to version 4.0.1 are vulnerable. No patch is presently available from the vendor, and the contact was not responded to.
Risk and Exploitability
The CVSS score is 6.9, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited yet possible industrial impact. The attack vector is remote, as the exploitation is performed through a crafted URL request to the server. An attacker could leverage this to reach internal hosts or retrieve sensitive data.
OpenCVE Enrichment