Mpv is a minimalist, open-source media player that has surfaced a small set of vulnerabilities centered on its core playback engine. The recurring weaknesses involve race conditions in shared resource handling, input validation gaps in media parsing, and format-string issues, reflecting the complexity of processing untrusted media files and managing concurrent I/O operations. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpv over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6360HIGH mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs i | Jan 28, 2018 | 8.8 | 28 | NO | NO |
CVE-2021-30145HIGH A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file. | May 18, 2021 | 7.8 | 26 | NO | NO |
CVE-2020-19824HIGH An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter. | Feb 17, 2023 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpv.
Media articles that mention a CVE ID that affects a product developed by Mpv — matched by CVE ID, not by vendor name.