Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vppr-73v3-3pc6

Опубликовано: 29 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

EPSS

Процентиль: 36%
0.00427
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.7
nvd
2 месяца назад

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

EPSS

Процентиль: 36%
0.00427
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-862