Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-29 18:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-57946
Mitre link : CVE-2026-57946
CVE.ORG link : CVE-2026-57946
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
