CVE-2026-57946
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
29/06/2026
Last modified:
14/07/2026
Description
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
3.70
Severity 3.x
LOW
References to Advisories, Solutions, and Tools
- https://github.com/iv-org/invidious/commit/c435dc1204970bcca06bcdcfb116c22092be22fd
- https://github.com/iv-org/invidious/issues/5775
- https://github.com/iv-org/invidious/pull/5776
- https://github.com/iv-org/invidious/releases/tag/v2.20260626.0
- https://www.vulncheck.com/advisories/invidious-private-playlist-disclosure-via-unauthenticated-rss-feed-endpoint
- https://github.com/iv-org/invidious/issues/5775



