Alltube Project maintains a focused video-download utility that exposes a narrow but strategically sensitive attack surface centered on URL handling and network request logic. The recurring vulnerability pattern reflects weaknesses in open redirect and server-side request forgery, typical of tools that parse and follow user-supplied or embedded URLs without strict validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alltube Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0692MEDIUM Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1. | Feb 21, 2022 | 6.1 | 26 | NO | YES |
CVE-2022-24739MEDIUM alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Requ | Mar 8, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alltube Project.
Media articles that mention a CVE ID that affects a product developed by Alltube Project — matched by CVE ID, not by vendor name.