VYPR

invidious

by Iv Org

CVEs (2)

  • CVE-2026-58447Jun 30, 2026
    risk 0.00cvss epss 0.00

    Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the…

  • CVE-2026-57946Jun 29, 2026
    risk 0.00cvss epss 0.00

    Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed…