Junglewise Threat Intelligence

CVE-2026-6219: aandrew-me ytDownloader command injection in Compressor Feature

CVE-2026-6219 · Severity: medium · CVSS 5.3 · Published 2026-04-13

Executive brief

ytDownloader is a tool used for downloading and processing video content. A security flaw in its video compression feature allows an attacker to execute unauthorized commands on a user's computer if the user processes a specially crafted file. This could lead to the theft of sensitive data, modification of files, or full control over the user's local system.

Technical details

A command injection vulnerability exists in the Compressor Feature of ytDownloader (up to version 3.20.2) within `src/compressor.js`. The application uses the `child_process.exec()` function to invoke `ffmpeg` by interpolating user-provided file paths directly into a shell command string. Because `exec()` spawns a shell, an attacker can use shell-significant characters (such as double quotes and ampersands) in a filename to break out of the intended command and execute arbitrary code. Exploitation requires the attacker to place a malicious file on the local system and convince a user to select or drag-and-drop that file into the compressor UI. To remediate this, the developer should replace `child_process.exec()` with `child_process.spawn()` or `execFile()`, passing arguments as an array to avoid shell interpretation.

Affected products

  • aandrew-me ytDownloader up to 3.20.2

Timeline

  • 2026-03-09: other: Vulnerability discovered
  • 2026-03-11: disclosed: Reported privately to maintainer and acknowledged
  • 2026-03-12: advisory: Public advisory published via GitHub Gist
  • 2026-04-13: other: CVE assigned and published to NVD

References