Josef Gajdusek reported that mpv 0.27.0 was vulnerable to an attack through it's youtube-dl hook. This could cause remote code execution. This upstream update creates of list of sure protocols to use through the hook.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0130.json"