Security Advisory

CVE-2026-57946

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-29 17:18:27
Last updated 2026-07-14 21:34:38
Assigner VulnCheck
CVSS score 6.3
State PUBLISHED

Description

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.