Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57946

Опубликовано: 29 июн. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

EPSS

Процентиль: 19%
0.00272
Низкий

3.7 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.7
github
2 месяца назад

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

EPSS

Процентиль: 19%
0.00272
Низкий

3.7 Low

CVSS3

Дефекты

CWE-862