CVE-2026-19352 Details
Description
A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.
A server-side request forgery (SSRF) vulnerability has been identified in LosslessCut versions through 3.69.0. The issue arises in the built-in HTTP API service, specifically within the file 'src/main/httpServer.ts'. The vulnerability allows local network access manipulation, but exploitation is complex and challenging. Although the maintainer downplays its criticality, citing its presence behind an experimental CLI flag, the vulnerability could be leveraged to relay NTLMv2 credentials, according to a report by a user named FoRever.
Users are advised to update to LosslessCut version 3.69.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 9, 2026CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mifi/lossless-cut/ | [email protected] | ProductSource CodeVendor |
| https://github.com/mifi/lossless-cut/commit/260802348955231442c4bae6c2d9d8ede947af0a | [email protected] | Source CodeVendor |
| https://my.feishu.cn/file/Jq4Ib90xeod3oPxlk77cv7jPnFe | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-19352 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/865910 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/387191 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/387191/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mifi lossless-cut | <= 3.69.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 9, 2026 | New CVE Received | [email protected] |
Volerion