External Control of File Name or Path in streamlink - #VU153943
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to read arbitrary local files accessible to the Streamlink process.
nThe vulnerability exists due to missing URL scheme validation in the DASH manifest parser's top-level <Location> handling when processing attacker-controlled manifests. A remote attacker can trick a user into opening an attacker-controlled URL serving a manifest with a crafted <Location> element containing a file:// URL to read arbitrary local files accessible to the Streamlink process.
nThe manifest reload path requires a dynamic manifest, whereas the segment path is available for both static and dynamic manifests. The segment path writes file contents to the user's configured stream output destination.