CVE-2026-85608

Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 15:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-85608

Mitre link : CVE-2026-85608

CVE.ORG link : CVE-2026-85608


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)