PatchSiren

zackees CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW zackees CVE published 2026-08-25

CVE-2026-79792

A high-severity OS command injection vulnerability was found in the ytdlp_download function of zackees transcribe-anything up to version 4.1.0. The vulnerability, tracked as CVE-2026-79792, allows remote attackers to inject OS commands via the URL argument. The attack complexity is rated as high and exploitability as difficult. Users of affected versions should verify and update their installations to pre [truncated]