Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages. | |
| Title | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T15:46:12.746Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85608
No data.
Status : Received
Published: 2026-09-04T15:17:41.707
Modified: 2026-09-04T15:17:41.707
Link: CVE-2026-85608
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:07Z