Critical severity9.9OSV Advisory· Published Dec 27, 2025· Updated Jun 17, 2026
CVE-2025-66203
CVE-2025-66203
Description
StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerability exists in the stream-vault application (SpiritApplication). The application allows administrators to configure yt-dlp arguments via the /admin/api/saveConfig endpoint without sufficient validation. These arguments are stored globally and subsequently used in YtDlpUtil.java when constructing the command line to execute yt-dlp. This issue has been patched in version 251126.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3251118+ 1 more
- (no CPE)range: 251118
- cpe:2.3:a:lemon8866:streamvault:*:*:*:*:*:*:*:*range: <251126
- Range: <251126
Patches
Vulnerability mechanics
References
2- github.com/lemon8866/StreamVault/security/advisories/GHSA-c747-q388-3v6mnvdExploitVendor Advisory
- github.com/lemon8866/StreamVault/releases/tag/251226nvdProductRelease Notes
News mentions
0No linked articles in our index yet.