4.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Basic Information
ID
CVE-2026-6219
Source
VulDB
Published
Apr 13, 2026 at 20:45
Affected Product
Vendor
aandrew-me
Product
ytDownloader
Version
3.20.0
Affected Versions
aandrew-me ytDownloader 3.20.0
aandrew-me ytDownloader 3.20.1
aandrew-me ytDownloader 3.20.2
aandrew-me ytDownloader 3.20.1
aandrew-me ytDownloader 3.20.2