Executive brief
Invidious, an open-source alternative YouTube front-end, contained a security flaw where private playlists were unintentionally accessible to the public. By accessing a specific RSS feed web address, anyone could view the contents of a private playlist and the owner's email address without needing to log in. This could lead to the exposure of personal viewing habits and contact information that users intended to keep private.
Technical details
A broken access control vulnerability exists in Invidious's RSS feed playlist endpoint (/feed/playlist/:plid). While the standard web and JSON API endpoints correctly enforce privacy settings for Invidious-native playlists (IDs starting with 'IV'), the RSS handler in 'src/invidious/routes/feeds.cr' failed to verify the playlist's privacy status before serialization. An unauthenticated remote attacker who knows or guesses a playlist ID can retrieve the full playlist title, video entries, and the owner's email address. The vulnerability is addressed in version 2.20260626.0 by adding a check to ensure private playlists are only served to their respective authors.
Affected products
- iv-org Invidious before 2.20260626.0
Timeline
- 2026-06-14: disclosed: Issue reported on GitHub
- 2026-06-15: patched: Fix merged into master branch
- 2026-06-27: patched: Version 2.20260626.0 released
- 2026-06-29: advisory: CVE published to NVD
References
- https://github.com/iv-org/invidious/commit/c435dc1204970bcca06bcdcfb116c22092be22fd
- https://github.com/iv-org/invidious/issues/5775
- https://github.com/iv-org/invidious/pull/5776
- https://github.com/iv-org/invidious/releases/tag/v2.20260626.0
- https://www.vulncheck.com/advisories/invidious-private-playlist-disclosure-via-unauthenticated-rss-feed-endpoint