{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/marcopiovanello/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:marcopiovanello:yt-dlp-web-ui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-93371"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["yt-dlp-web-ui (\u003c= v4)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["marcopiovanello"],"content_html":"\u003cp\u003eThe application yt-dlp-web-ui, developed by marcopiovanello, contains a critical command injection vulnerability identified as CVE-2026-93371. The flaw resides in the NewGenericDownload function within the source file server/internal/downloaders/generic.go. This vulnerability occurs due to improper sanitization of the params argument before it is passed to underlying system commands.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can supply malicious input via the params parameter to trigger arbitrary command execution on the host server. This flaw poses a high risk to availability, integrity, and confidentiality of the host environment. The vulnerability has been publicly disclosed with functional exploit potential, necessitating immediate remediation. Users must apply the security patch identified by commit c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897 or upgrade to a version where this issue is resolved.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-93371 allows an unauthenticated remote attacker to gain remote code execution (RCE) on the server running yt-dlp-web-ui. This can lead to full system compromise, exfiltration of stored data, or the use of the server as a node in further malicious activities. Given the public availability of exploitation details, the likelihood of automated exploitation attempts targeting internet-facing instances is elevated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade yt-dlp-web-ui instances to a version containing the fix for CVE-2026-93371.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch c7ad3bd79c7c520a7d17e7f2ba19d962be8e7897 immediately if an upgrade is not feasible.\u003c/li\u003e\n\u003cli\u003eRestrict access to the web interface using network-level controls (e.g., VPN or IP whitelisting) until patching is complete.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing suspicious shell metacharacters (e.g., ;, |, \u0026amp;, $, `) directed at endpoints related to the download functionality.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T04:02:59Z","date_published":"2026-09-18T04:02:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93371/","summary":"An unauthenticated remote command injection vulnerability in yt-dlp-web-ui version 4 and earlier allows remote attackers to execute arbitrary system commands via the params argument.","title":"Command Injection in marcopiovanello yt-dlp-web-ui","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-93371/"}],"language":"en","title":"CraftedSignal Threat Feed - Marcopiovanello","version":"https://jsonfeed.org/version/1.1"}