{"id":"CVE-2021-30145","details":"A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.","modified":"2026-07-08T20:04:17.768156Z","published":"2021-05-18T14:15:07.377Z","related":["openSUSE-SU-2021:0788-1","openSUSE-SU-2021:0798-1"],"references":[{"type":"ADVISORY","url":"https://github.com/mpv-player/mpv/releases/tag/v0.33.1"},{"type":"ADVISORY","url":"https://mpv.io"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202107-46"},{"type":"FIX","url":"https://github.com/mpv-player/mpv/commit/d0c530919d8cd4d7a774e38ab064e0fabdae34e6"},{"type":"EVIDENCE","url":"https://devel0pment.de/?p=2217"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mpv-player/mpv","events":[{"introduced":"0"},{"last_affected":"0728b514980cccd13543eea53a8e23332e233a6c"},{"fixed":"d0c530919d8cd4d7a774e38ab064e0fabdae34e6"},{"fixed":"b5d3e43198b9d57af5620b63537885aaa41fa8cd"}],"database_specific":{"cpe":"cpe:2.3:a:mpv:mpv:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.33.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.33.0","v0.32.0","v0.31.0","v0.29.0","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-30145.json","vanir_signatures_modified":"2026-07-08T20:04:17Z","vanir_signatures":[{"target":{"file":"demux/demux_mf.c","function":"open_mf_pattern"},"deprecated":false,"digest":{"function_hash":"268634330912393980160582075139174200355","length":2529},"id":"CVE-2021-30145-7c714005","signature_type":"Function","signature_version":"v1","source":"https://github.com/mpv-player/mpv/commit/d0c530919d8cd4d7a774e38ab064e0fabdae34e6"},{"deprecated":false,"digest":{"line_hashes":["318278708610111311971907503341767063621","20400393116502452763656028356723097255","2518238306090257716179303030090564964","122700104744205355818586971563960571964","190191767106811564608045251026599596882","28396784055268661443982855327607510881","129441837851678876694802442058186216748","99586014603262892290593702810603438397","103567284091188742513705697402229084886","133517497564468559407418282955546792386"],"threshold":0.9},"id":"CVE-2021-30145-e23b7691","signature_type":"Line","signature_version":"v1","source":"https://github.com/mpv-player/mpv/commit/d0c530919d8cd4d7a774e38ab064e0fabdae34e6","target":{"file":"demux/demux_mf.c"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}