SB20261007250 - Path traversal in streamlink
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) External Control of File Name or Path (CVE-ID: N/A)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read arbitrary local files accessible to the Streamlink process.
nThe vulnerability exists due to missing URL scheme validation in the DASH manifest parser's top-level <Location> handling when processing attacker-controlled manifests. A remote attacker can trick a user into opening an attacker-controlled URL serving a manifest with a crafted <Location> element containing a file:// URL to read arbitrary local files accessible to the Streamlink process.
nThe manifest reload path requires a dynamic manifest, whereas the segment path is available for both static and dynamic manifests. The segment path writes file contents to the user's configured stream output destination.
Remediation
Install update from vendor's website.