VYPR

Douyin_TikTok_Download_API

by Evil0ctal

CVEs (1)

  • CVE-2026-85608HigSep 4, 2026
    risk 0.49cvss 7.5epss

    Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request…