A vulnerability was found in mifi lossless-cut up to 3.69.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-19352. The attack requires access to the local network. Furthermore, an exploit is available.
It is best practice to apply a patch to resolve this issue.
The project maintainer provides this view: “I’m not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn’t really a LosslessCut bug.” The CVSS vector reflects the high level of pre-requisites.