SB20261007250 - Path traversal in streamlink



SB20261007250 - Path traversal in streamlink

Published: October 7, 2026

Security Bulletin ID SB20261007250
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) External Control of File Name or Path (CVE-ID: N/A)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read arbitrary local files accessible to the Streamlink process.

n

The vulnerability exists due to missing URL scheme validation in the DASH manifest parser's top-level <Location> handling when processing attacker-controlled manifests. A remote attacker can trick a user into opening an attacker-controlled URL serving a manifest with a crafted <Location> element containing a file:// URL to read arbitrary local files accessible to the Streamlink process.

n

The manifest reload path requires a dynamic manifest, whereas the segment path is available for both static and dynamic manifests. The segment path writes file contents to the user's configured stream output destination.


Remediation

Install update from vendor's website.