Only the latest release of chunder receives security fixes.
Please do not open a public issue for security problems. Instead, use GitHub's private vulnerability reporting on the chunder repository.
You'll get an acknowledgement within a few days. Once a fix ships, the report and credit are published in the release notes.
chunder shells out to ffmpeg/ffplay and fetches media from
googlevideo.com hosts resolved via YouTube's player API. Reports about
malicious media files exploiting ffmpeg should go to the
FFmpeg security team; reports about how
chunder invokes them belong here.