VYPR

xidown

by Xidown

CVEs (1)

  • CVE-2026-71212Aug 5, 2026
    risk 0.00cvss epss 0.00

    xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in…