Sceawere
Vulnerability Detail
CVE-2026-100901UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF in youtube-downloader stream.php
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 5h ago
- Vendor
- athlon1600
- Product
- youtube-downloader
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T03:16:38.803Z",
"pubdate": "2026-09-28T03:16:38.803Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the athlon1600 youtube-downloader library up to version 4.0.1. The flaw resides within the stream function of public/stream.php, where user-supplied input via the 'url' argument is insufficiently sanitized before being processed by server-side cURL requests.\nThis vulnerability allows an unauthenticated remote attacker to force the web server to send arbitrary HTTP/HTTPS requests to internal or external destinations. By manipulating the target URL, an attacker can bypass firewall restrictions, probe internal network services, access metadata services (such as AWS Instance Metadata Service), or perform port scanning on the local infrastructure.\nThe risk is exacerbated by the existence of a public exploit. While commit 6ffe823 attempted to mitigate the issue by restricting cURL protocols and implementing redirect caps, it failed to implement necessary destination host validation or allowlisting, rendering the primary attack vector still viable.",
"technicalDetails": "The vulnerability is located in the public/stream.php script, specifically within the stream function, which utilizes the PHP cURL library to fetch remote content. The application accepts a 'url' parameter provided by the user, which is passed directly to the cURL handler without adequate validation or sanitization of the destination host.\nRoot cause analysis reveals a lack of server-side input validation or address filtering. The application fails to resolve or verify the resolved IP address of the user-provided URL against a blocklist of reserved IP ranges (e.g., 127.0.0.1, 169.254.169.254, or internal RFC 1918 addresses). Because the application acts as a proxy for the request, it inherently trusts the input provided by the client, allowing the attacker to specify any target reachable by the host server.\nThe attack flow proceeds as follows: 1) The attacker initiates a GET or POST request to public/stream.php, appending the 'url' parameter with a malicious URI. 2) The server-side script initializes a cURL handle and assigns the attacker's URL to the CURLOPT_URL option. 3) The server executes the request, essentially masquerading the attacker's intent as legitimate server traffic. 4) The server receives the response from the targeted internal resource and relays it back to the client or processes the content.\nAlthough commit 6ffe823 introduced CURLOPT_PROTOCOLS for http/https and a limit on MAXREDIRS, these controls are insufficient. These settings only restrict the protocol scheme and the number of hops; they do not prevent the request from being directed at unauthorized hosts, such as sensitive loopback interfaces or internal management APIs.\nImpacts of successful exploitation include: (A) Internal Network Reconnaissance: The attacker can probe open ports and services behind the firewall. (B) Sensitive Data Exfiltration: The attacker may access internal web pages or configuration endpoints that are only accessible from within the network perimeter. (C) Cloud Metadata Theft: In cloud-hosted environments, attackers can query the Instance Metadata Service (IMDS) to retrieve sensitive IAM credentials, network configurations, or security tokens.\nThis vulnerability is remotely exploitable without authentication, as the functionality is exposed to the public-facing interface of the web application. The absence of strict allowlisting of permissible destination domains or IP addresses remains the critical failure point in the security implementation."
}