Description
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: 1.4% Low
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

The flaw exists in the NewGenericDownload function of the yt-dlp-web-ui tool, where unsanitized arguments are passed to the operating system shell. This injection vulnerability allows an attacker to execute arbitrary commands on the host running the application, in effect giving remote command execution power. The weakness is classified as CWE-74 and CWE-77, reflecting unsanitized input and lack of execution‑context validation. The stated description notes that the flaw can be abused remotely and that a public exploit is available.

Affected Systems

Yt-dlp-web-ui hosted by marcopiovanello on GitHub is affected for all releases up to and including v4. The vulnerable code path is in server/internal/downloaders/generic.go. Any deployment of the tool running v4 or earlier carries the risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a serious level of severity, and the EPSS score of 1% suggests exploitation is unlikely at the moment but not impossible. The vulnerability is not listed in the CISA KEV catalog. Because the text states the attack can be launched remotely and no authentication requirement is specified, it is inferred that the endpoint might be reachable without credentials, implying a potential for unauthenticated exploitation. Attackers could leverage crafted input to the NewGenericDownload API to execute arbitrary commands on the underlying operating system, leading to full compromise of the host.

Generated by OpenCVE AI on September 19, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897 to the yt-dlp-web-ui source.
  • If the patch cannot be applied immediately, disable or remove the NewGenericDownload functionality from the deployment to block exploitation.
  • Limit network exposure of the yt-dlp-web-ui by restricting inbound traffic to trusted IP addresses or an internal network.

Generated by OpenCVE AI on September 19, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The name of the patch is c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897. A patch should be applied to remediate this issue.
Title marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection
First Time appeared Marcopiovanello
Marcopiovanello yt-dlp-web-ui
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:marcopiovanello:yt-dlp-web-ui:*:*:*:*:*:*:*:*
Vendors & Products Marcopiovanello
Marcopiovanello yt-dlp-web-ui
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Marcopiovanello Yt-dlp-web-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:44:33.432Z

Reserved: 2026-09-17T19:27:07.761Z

Link: CVE-2026-93371

cve-icon Vulnrichment

Updated: 2026-09-22T15:05:11.937Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T03:16:33.563

Modified: 2026-09-22T16:18:13.187

Link: CVE-2026-93371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')