Impact
The flaw exists in the NewGenericDownload function of the yt-dlp-web-ui tool, where unsanitized arguments are passed to the operating system shell. This injection vulnerability allows an attacker to execute arbitrary commands on the host running the application, in effect giving remote command execution power. The weakness is classified as CWE-74 and CWE-77, reflecting unsanitized input and lack of execution‑context validation. The stated description notes that the flaw can be abused remotely and that a public exploit is available.
Affected Systems
Yt-dlp-web-ui hosted by marcopiovanello on GitHub is affected for all releases up to and including v4. The vulnerable code path is in server/internal/downloaders/generic.go. Any deployment of the tool running v4 or earlier carries the risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a serious level of severity, and the EPSS score of 1% suggests exploitation is unlikely at the moment but not impossible. The vulnerability is not listed in the CISA KEV catalog. Because the text states the attack can be launched remotely and no authentication requirement is specified, it is inferred that the endpoint might be reachable without credentials, implying a potential for unauthenticated exploitation. Attackers could leverage crafted input to the NewGenericDownload API to execute arbitrary commands on the underlying operating system, leading to full compromise of the host.
OpenCVE Enrichment