CVE-2025-66203
EUVD-2025-20546827.12.2025, 00:15
StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient validation. These arguments are stored globally and subsequently used in YtDlpUtil.java when constructing the command line to execute yt-dlp. This issue has been patched in version 251126.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lemon8866 | streamvault | 𝑥 < 251126 |
𝑥
= Vulnerable software versions