CVE-2026-54254: Pixeldrain API key shared with unverified thirdparty sites
When processing Pixeldrain URLs, cyberdrop-dl-patched could send an Authorization header that includes the user’s API key to unverified hosts.
References
- docs.pixeldrain.com/questions_and_answers/
- github.com/Cyberdrop-DL/cyberdrop-dl/commit/4479555ae3f9d56d7657d6179a5bac3123eb4e2b
- github.com/Cyberdrop-DL/cyberdrop-dl/releases/tag/9.14.0
- github.com/Cyberdrop-DL/cyberdrop-dl/security/advisories/GHSA-f5pf-q7c7-m3vv
- github.com/advisories/GHSA-f5pf-q7c7-m3vv
- nvd.nist.gov/vuln/detail/CVE-2026-54254
Code Behaviors & Features
Detect and mitigate CVE-2026-54254 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →