High severity7.5NVD Advisory· Published Sep 4, 2026· Updated Sep 4, 2026
CVE-2026-85608
CVE-2026-85608
Description
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4.1.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.