Filtered by vendor Evil0ctal Subscriptions
Filtered by product Douyin Tiktok Download Api Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-85608 1 Evil0ctal 1 Douyin Tiktok Download Api 2026-09-07 7.5 High
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.