mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. For example, an av://lavfi:ladspa=file= URL signifies that the product should call dlopen on a shared object file located at an arbitrary local pathname. The issue exists because the product does not consider that youtube-dl can provide a potentially unsafe URL.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-mpv | Aug 22, 2024 | Jan 28, 2018 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 28, 2018 | |
| Debian | debian-upgrade-mpv | Feb 8, 2018 | Jan 27, 2018 | |
| Freebsd | freebsd-upgrade-package-mpv | Feb 10, 2018 | Feb 9, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-media-video-mpv | May 15, 2018 | Jan 27, 2018 | |
| Suse | — | suse-upgrade-libmpv1suse-upgrade-libmpv1-debuginfosuse-upgrade-mpvsuse-upgrade-mpv-bash-completionsuse-upgrade-mpv-debuginfosuse-upgrade-mpv-develsuse-upgrade-mpv-zsh-completion | Feb 20, 2018 | Jan 27, 2018 |
| Ubuntu | ubuntu-upgrade-mpv | Nov 19, 2024 | Jan 28, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub