Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
iSponsorBlockTV 2.11.0 behebt Blind-SSRF in DIAL-Autoerkennung
iSponsorBlockTV v2.11.0 behebt eine Blind-SSRF-Schwachstelle (CVE-2026-77597) in der DIAL-Autoerkennung, über die ein manipuliertes Gerät im selben LAN eine beliebige URL abrufen lassen konnte, und ein Update wird für alle Nutzer empfohlen.
Fixed blind SSRF on DIAL auto discovery
Fixes advisory: GHSA-56v3-jrq2-4q9m / CVE-2026-77597 It's recommended for all users to update to this latest version (v2.11.0) This issue could allow an attacker controlled device on the same lan as iSponsorBlockTV to request an arbitrary URL by abusing the DIAL auto-discovery. It'd be able to either:
- show a debug log line
- __main__ - DEBUG - Discovered device at <attacker controlled URL>, processing...(which is normally disabled and won't be shown in the actual configurator since textual doesn't show logs unless running in dev mode and launching a second terminal to inspect log output), and make a single GET request to an "attacker controlled" url which does not leak any information back to iSponsorBlockTV itself and swallows any sort of error (parsing or an invalid response from not being a real DIAL server) (dial_client.pyL131-L133) …