CVE-2023-35934 describes a cookie leakage vulnerability in yt-dlp, a command-line video downloader, affecting versions prior to 2023.07.06. This flaw allows sensitive cookies to be inadvertently sent to unintended hosts during HTTP redirects or when downloading fragmented content, potentially exposing user authentication information. Rated with a CVSS score of 8.2 (High), the vulnerability has a network attack vector and low attack complexity, requiring user interaction (e.g., clicking a malicious link) to trigger. Successful exploitation could lead to high confidentiality impact due to cookie exposure, but has low integrity and no availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or immediate threat perception.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:youtube-dlc_project:youtube-dlc:*:*:*:*:*:*:*:* | ||
>= 2015.01.25CPE matchmatch criteria | cpe:2.3:a:yt-dl:youtube-dl:*:*:*:*:*:*:*:* | ||
< 2023.07.06CPE matchmatch criteria | cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:-:*:*:* | ||
< 2023.07.06.185519CPE matchmatch criteria | cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:nightly:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.