mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. For example, an av://lavfi:ladspa=file= URL signifies that the product should call dlopen on a shared object file located at an arbitrary local pathname. The issue exists because the product does not consider that youtube-dl can provide a potentially unsafe URL.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mpv | Aug 22, 2024 | Jan 28, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 28, 2018 |
| Debian | — | Upgrade mpv | Feb 8, 2018 | Jan 27, 2018 |
| Freebsd | — | Upgrade mpv | Feb 10, 2018 | Feb 9, 2018 |
| Gentoo Linux | — | Upgrade media-video/mpv. | May 15, 2018 | Jan 27, 2018 |
| Suse | — | Upgrade libmpv1Upgrade mpv-bash-completionUpgrade mpvUpgrade mpv-zsh-completionUpgrade libmpv1-debuginfoUpgrade mpv-debuginfoUpgrade mpv-devel | Feb 20, 2018 | Jan 27, 2018 |
| Ubuntu | — | Upgrade mpv | Nov 19, 2024 | Jan 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub