CVE-2026-85608 Details
Description
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages.
A server-side request forgery (SSRF) vulnerability has been identified in the Douyin TikTok Download API, specifically in version 4.1.2. The vulnerability exists in the '/api/download' and '/api/hybrid/video_data' endpoints, where unauthenticated attackers can exploit the 'url' query parameter to fetch arbitrary URLs. This exploitation can target internal services, including cloud metadata endpoints, potentially leading to the retrieval of sensitive credentials through error message responses.
Users are advised to update to Douyin TikTok Download API version 5.1.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Evil0ctal/Douyin_TikTok_Download_API/issues/729 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Evil0ctal/Douyin_TikTok_Download_API | [email protected] | ProductSource CodeVendor |
| https://github.com/Evil0ctal/Douyin_TikTok_Download_API/blob/V4.1.2/crawlers/douyin/web/utils.py | [email protected] | Source CodeVendor |
| https://github.com/Evil0ctal/Douyin_TikTok_Download_API/issues/729 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/douyin-tiktok-download-api-4.1.2-ssrf-via-url-parameter | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Evil0ctal Douyin_TikTok_Download_API | <= 4.1.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion