Executive brief
ytDownloader is a tool used for downloading and processing video content. A security flaw in its video compression feature allows an attacker to execute unauthorized commands on a user's computer if the user processes a specially crafted file. This could lead to the theft of sensitive data, modification of files, or full control over the user's local system.
Technical details
A command injection vulnerability exists in the Compressor Feature of ytDownloader (up to version 3.20.2) within `src/compressor.js`. The application uses the `child_process.exec()` function to invoke `ffmpeg` by interpolating user-provided file paths directly into a shell command string. Because `exec()` spawns a shell, an attacker can use shell-significant characters (such as double quotes and ampersands) in a filename to break out of the intended command and execute arbitrary code. Exploitation requires the attacker to place a malicious file on the local system and convince a user to select or drag-and-drop that file into the compressor UI. To remediate this, the developer should replace `child_process.exec()` with `child_process.spawn()` or `execFile()`, passing arguments as an array to avoid shell interpretation.
Affected products
- aandrew-me ytDownloader up to 3.20.2
Timeline
- 2026-03-09: other: Vulnerability discovered
- 2026-03-11: disclosed: Reported privately to maintainer and acknowledged
- 2026-03-12: advisory: Public advisory published via GitHub Gist
- 2026-04-13: other: CVE assigned and published to NVD