Skip to main content
EPSS 0.1%top 98%

CVE-2026-71212: CWE-88 Argument Injection in indravoyager xidown

0
Medium
Published: 08/05/2026 (08/05/2026, 08:16:00 UTC)
Source: CVE Database V5
Vendor/Project: indravoyager
Product: xidown

Description

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in the codebase.

CVSS v3.1

Score 4.4medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Affected software

indravoyager

xidown

Affected versions
>=0 <=1.25.1.19

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 14:26:39 UTC

Technical Analysis

The xidown application builds yt-dlp command-line calls by appending user-supplied or scanned URLs directly as positional arguments without inserting a '--' end-of-options marker or validating the URL scheme. This behavior corresponds to CWE-88 (Argument Injection), where crafted input could be interpreted as additional command-line options or arguments, potentially altering the intended command execution. The vulnerability is present in xidown's core/scanner.py and downloader.py components. No patch or official remediation guidance is currently available.

Potential Impact

The vulnerability allows an attacker with local access (AV:L) and no privileges (PR:N) but requiring user interaction (UI:R) to inject additional command-line arguments into the yt-dlp invocation. This can lead to limited integrity impact (I:L) and availability impact (A:L), such as executing unintended commands or disrupting normal operation. Confidentiality is not impacted. The overall CVSS score is 4.4 (medium).

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid running xidown with untrusted URLs or inputs that could be crafted to inject command-line arguments. Consider manually reviewing or sanitizing input URLs before use.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
TuranSec
Date Reserved
2026-08-05T06:56:15.799Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a72e5cdbf8831d5397357f0

Added to database: 08/05/2026, 07:27:09 UTC

Last enriched: 08/12/2026, 14:26:39 UTC

Last updated: 09/17/2026, 22:01:38 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses