External Control of File Name or Path in streamlink - #VU153943

 

External Control of File Name or Path in streamlink - #VU153943

Published: October 7, 2026


Vulnerability identifier: #VU153943
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read arbitrary local files accessible to the Streamlink process.

n

The vulnerability exists due to missing URL scheme validation in the DASH manifest parser's top-level <Location> handling when processing attacker-controlled manifests. A remote attacker can trick a user into opening an attacker-controlled URL serving a manifest with a crafted <Location> element containing a file:// URL to read arbitrary local files accessible to the Streamlink process.

n

The manifest reload path requires a dynamic manifest, whereas the segment path is available for both static and dynamic manifests. The segment path writes file contents to the user's configured stream output destination.


Affected software

streamlink

Remediation

Install security update from vendor's website.

streamlink - update to 8.6.2

External References

Related Security Bulletins