WhisperX tag archive

#Critical Bug

This page collects WhisperX intelligence signals tagged #Critical Bug. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-14 13:22:47 · GitHub Issues

1. Critical Security Flaw: 'tls_domain' Parameter Exposed as Unsanitized Config Injection Vector

A critical security vulnerability has been identified where the user-supplied `tls_domain` parameter is directly placed into a `re.sub` replacement string without any sanitization. This creates a dangerous configuration injection vector, allowing a malicious `tls_domain` value to inject arbitrary regex replacement patt...