douyin-downloader
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalydouyin.js
LOWAnomalyLOW
douyin.js
No direct evidence of intentional malware/backdoor behavior in this module. The dominant security concerns are (1) possible path traversal/arbitrary file write due to insufficient validation of the derived video_id used in filesystem paths, and (2) SSRF-adjacent behavior from unrestricted redirect following to arbitrary redirect targets. Additional non-malicious but material risks include privacy-sensitive upload of full audio to an external transcription API and operational exposure from running ffmpeg/ffprobe on untrusted downloaded media.
Confidence: 63%Severity: 68%
Audit Metadata