← back
CVE-2026-58447highCWE-639

Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.1epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the playlist endpoint. Attackers can obtain per-video index values from the public playlist JSON API and submit them to the playlist video deletion endpoint without ownership validation, permanently removing videos from playlists they do not own.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
iv-org · Invidious
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.