Junglewise Threat Intelligence

CVE-2026-93371: marcopiovanello yt-dlp-web-ui command injection in NewGenericDownload

CVE-2026-93371 · Severity: high · CVSS 8.3 · Published 2026-09-18

Executive brief

yt-dlp-web-ui is a web interface and RPC server for downloading media using yt-dlp. An attacker can inject arbitrary commands through the params argument in the NewGenericDownload function, gaining remote code execution on the server without requiring authentication. This could allow an attacker to take control of the system running the web UI.

Technical details

The vulnerability is a command injection flaw in the NewGenericDownload function located in server/internal/downloaders/generic.go. The params argument is passed to a downloader without proper validation or sanitization, allowing shell metacharacters and command separators to be executed. The attack is remotely exploitable over the network with no authentication required. An attacker can execute arbitrary commands with the privileges of the yt-dlp-web-ui process. The fix (commit c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897) implements parameter whitelisting to restrict allowed arguments.

Affected products

  • marcopiovanello yt-dlp-web-ui up to v4

Timeline

  • 2026-09-18: disclosed: Public disclosure date
  • 2026-08-21: patched: Patch available at commit c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897

References