CVE-2018-6360 describes a critical arbitrary code execution vulnerability in mpv versions up to 0.28.0, affecting Debian Linux distributions. This flaw allows remote attackers to execute arbitrary code by tricking a user into visiting a crafted website. The vulnerability stems from mpv's handling of VIDEO elements and arbitrary URLs in the src attribute without proper protocol whitelisting, specifically enabling the use of unsafe URLs provided by youtube-dl. With a CVSS score of 8.8 (High), this vulnerability has a network attack vector, low attack complexity, and requires user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low, indicating a lower likelihood of exploitation, the FAUCET Risk Score of 70/100 suggests a significant risk. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability also lacks community discussion and media coverage, suggesting it has not garnered significant attention from the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.28.0CPE matchmatch criteria | cpe:2.3:a:mpv:mpv:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.