{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/youtube-downloader--4.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:athlon1600:youtube_downloader:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100901"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["youtube-downloader (\u003c= 4.0.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","ssrf","vulnerability"],"_cs_type":"advisory","_cs_vendors":["athlon1600"],"content_html":"\u003cp\u003eA server-side request forgery (SSRF) vulnerability has been identified in the athlon1600 youtube-downloader project, affecting versions up to 4.0.1. The flaw exists within the 'stream' function of the 'public/stream.php' file, where user-supplied input via the 'url' argument is not correctly sanitized or validated before being used to initiate outbound requests.\u003c/p\u003e\n\u003cp\u003eAlthough a patch attempt (commit 6ffe823) was introduced to mitigate potential issues by adding 'CURLOPT_PROTOCOLS' restrictions and a 'MAXREDIRS' cap, the implementation fails to restrict the destination host, leaving the application vulnerable to remote exploitation. The vulnerability allows an attacker to force the server to initiate arbitrary HTTP or HTTPS requests, potentially exposing internal network resources or sensitive metadata services to unauthorized access. The vendor has remained unresponsive to disclosure attempts regarding this flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to perform SSRF attacks. This may result in unauthorized access to internal network services, private APIs, or cloud metadata endpoints that are otherwise inaccessible from the public internet, potentially leading to data exfiltration or internal reconnaissance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit web server access logs for requests directed at 'public/stream.php' containing suspicious 'url' parameter values targeting internal IP addresses (e.g., 169.254.169.254, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).\u003c/li\u003e\n\u003cli\u003eImplement an allowlist of permitted destination domains or URL patterns for the 'stream' function if the application requirements permit.\u003c/li\u003e\n\u003cli\u003eRestrict outbound network traffic from web server instances to prevent unauthorized internal scanning, particularly toward sensitive infrastructure segments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-28T05:12:06Z","date_published":"2026-09-28T05:12:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ssrf/","summary":"The youtube-downloader package contains an SSRF vulnerability in the stream function of public/stream.php allowing remote attackers to perform unauthorized outbound requests.","title":"Server-Side Request Forgery in youtube-downloader","url":"https://feed.craftedsignal.io/briefs/2026-09-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Youtube-Downloader (\u003c= 4.0.1)","version":"https://jsonfeed.org/version/1.1"}