CVE-2026-57946

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-29 18:16

Updated : 2026-07-14 22:17


NVD link : CVE-2026-57946

Mitre link : CVE-2026-57946

CVE.ORG link : CVE-2026-57946


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization