Skip to content

RCE in /yt-stream route #68

@gronke

Description

@gronke

The url query param might contain shell escape or pipeline characters, such as | or ;, resulting in remote code execution:

exec("livestreamer --player=mplayer https://www.youtube.com/watch?v=" + req.params.url + " best");

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions