External risk intelligence

StreamVault RCE via yt-dlp Argument Injection

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-66203

The vulnerability exists within an administrative API endpoint (/admin/api/saveConfig) of a web-based application. Such management interfaces are commonly exposed or accessible within internal web environments, making them plausibly reachable in deployments where the application's administrative surface is exposed to the network.

OS Command Injection

Lemon8866 Streamvault

before 251126

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the StreamVault video download integration solution that could allow for remote code execution. This issue stems from how the application handles administrator-configured arguments for the yt-dlp tool, which are used when constructing commands to execute. The problem has been addressed in a recent update.

  • Malicious configuration commands could execute code.
  • Remember: Admin controls are a potential entry point.
  • Confirm if your video download solution is affected.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges can target the StreamVault application by accessing its administrative API. By sending specially crafted arguments to the configuration saving endpoint, the attacker can influence how an external tool is executed, potentially leading to the execution of arbitrary code on the server.

  • Requires administrator access.
  • Triggered via configuration API endpoint.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated administrator to execute arbitrary commands on the server, potentially impacting the application's availability and the confidentiality and integrity of any data it processes, when they use the admin API to configure video download arguments.

  • Server command execution.
  • Admin API configuration manipulation.
  • Service disruption or data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The StreamVault application's administrative API is the likely entry point for this remote code execution vulnerability, suggesting that platform or application owners responsible for managing this integration solution should take the lead. The immediate priority is to identify all instances of StreamVault, determine their network exposure, and confirm their business criticality to accurately assess risk before planning remediation.

  • Identify all StreamVault instances.
  • Verify external reachability and business impact.
  • Coordinate patching or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is StreamVault?

StreamVault is a software integration solution designed to handle video downloads. It functions as a middleware tool, utilizing external utilities like yt-dlp to process and retrieve media content. It is typically managed through web-based administrative interfaces that allow users to configure how these background download tasks operate.

What does this CVE-2025-66203 vulnerability mean?

This is an OS Command Injection vulnerability, classified as CWE-78. It means the application improperly handles input provided to the administrative configuration settings. Because these settings are passed directly to the system to run download tools, an attacker can inject malicious commands into the configuration, causing the server to execute unintended, harmful code instead of legitimate download instructions.

How is this vulnerability triggered?

The issue is triggered when an attacker with administrative access submits specially crafted arguments to the /admin/api/saveConfig endpoint. It is important to note that simply visiting the application or triggering standard video downloads does not cause this; the flaw specifically requires the submission of malicious configuration data through that specific administrative API to alter the underlying command-line execution.

Why should I care about this issue?

Halo Surface Signal indicates that because this vulnerability exists within an administrative management API, it is highly relevant if your StreamVault instance is reachable over a network. If your administrative interface is exposed—either intentionally for remote management or inadvertently—attackers could leverage this entry point to gain control over the server hosting your application, even if they are not already logged in as a legitimate administrator.

Do I need to take action if I use StreamVault?

Yes. First, locate all running instances of StreamVault within your environment to determine which are currently reachable over the network. If your version is earlier than 251126, you are affected. The primary response is to update your software to version 251126 or later, which contains the necessary validation logic to prevent malicious command injection.

References