← Back

Lemon8866

lemon8866

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Streamvault
streamvault

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lemon8866
1Streamvault
Mar 9, 2026
Dec 27, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators...Show more
StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient validation. These arguments are stored globally and subsequently used in YtDlpUtil.java when constructing the command line to execute yt-dlp. This issue has been patched in version 251126.Show less