LOW
zackees
CVE published 2026-08-25
CVE-2026-79792
A high-severity OS command injection vulnerability was found in the ytdlp_download function of zackees transcribe-anything up to version 4.1.0. The vulnerability, tracked as CVE-2026-79792, allows remote attackers to inject OS commands via the URL argument. The attack complexity is rated as high and exploitability as difficult. Users of affected versions should verify and update their installations to pre [truncated]