{"id":"CVE-2026-85608","summary":"Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter","details":"Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.","modified":"2026-09-06T03:47:18.165820839Z","published":"2026-09-04T14:32:09.875Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85608.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85608.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85608"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/douyin-tiktok-download-api-4.1.2-ssrf-via-url-parameter"},{"type":"REPORT","url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API/issues/729"},{"type":"PACKAGE","url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API"},{"type":"ARTICLE","url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API/blob/V4.1.2/crawlers/douyin/web/utils.py"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/evil0ctal/douyin_tiktok_download_api","events":[{"introduced":"0"},{"fixed":"ab87be43afd2301ef8c6c320f01c015114007295"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"last_affected":"4.1.2"},{"fixed":"4.1.2"}]}}],"versions":["V4.1.0","V4.0.9","V4.0.8","V4.0.6","V4.0.5","V4.0.4","V4.0.0","V3.2.2","V3.1.9","V3.1.8","V3.1.3","V3.1.2","V3.1.1","RIP_Xinjiang","V3.1.0","V3.01","V3.00","ZidIYXBweSBCaXJ0aGRheSB0byB7RXZpbDBjdGFsfSc","V2.09","V2.08","V2.07","V2.06","V2.05","V2.04","V2.03","V2.02","V2.01","V2.0","1.11","1.10","1.09","Spring_Festival🧨","File_format","TikTok_Fix","API_Fix","TikTok_Supported","Log","Add_Language","TikTok","Zip"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85608.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}