CVE-2026-58447 Details
Description
Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the playlist endpoint. Attackers can obtain per-video index values from the public playlist JSON API and submit them to the playlist video deletion endpoint without ownership validation, permanently removing videos from playlists they do not own.
A broken object level authorization vulnerability has been identified in Invidious versions through 2.20260626.0. This vulnerability allows authenticated users to delete videos from other users' playlists by sending an arbitrary global video index to the playlist video deletion endpoint, without any ownership validation. The affected endpoint is part of the Invidious playlist management system.
Users can update to Invidious version 2.20260626.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/iv-org/invidious/issues/5777 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/iv-org/invidious/commit/77ad41678b45c4f6815940123f1796fc51259f45 | [email protected] | Source CodeVendor |
| https://github.com/iv-org/invidious/issues/5777 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/iv-org/invidious/pull/5790 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/invidious-cross-user-playlist-video-deletion-via-missing-ownership-check | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Invidious | <= 2.20260626.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion