CPE
Bilibili Desktop versions 1.18.0 and earlier are vulnerable to remote command execution and credential theft due to disabled TLS certificate verification and the execution of unsigned remote JavaScript configurations.