Impact
Douyin_TikTok_Download_API versions up to 4.1.2 allow an attacker who can issue HTTP requests to the /api/download and /api/hybrid/video_data endpoints to supply an arbitrary url query parameter. The server then fetches that URL and returns the response body, effectively performing an SSRF. The description indicates that attackers can target internal services such as cloud‑metadata endpoints; the response can contain sensitive credentials disclosed in error messages. This vulnerability can lead to confidentiality loss of internal secrets, credential exposure, and potential lateral movement within the environment.
Affected Systems
The affected product is Evil0ctal:Douyin_TikTok_Download_API, version 4.1.2. No other affected versions or products are listed. Systems running this exact version are at risk.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity, and the lack of authentication barriers makes exploitation trivial once the attacker can reach the vulnerable API. The EPSS score is not available, but the vulnerability is actionable by simply sending a crafted HTTP request. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw by sending a request containing a malicious url parameter, triggering the server to pull data from internal endpoints and deliver it back to the attacker.
OpenCVE Enrichment