PatchSiren

yt-dlp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH yt-dlp CVE published 2026-07-08

CVE-2026-55404

CVE-2026-55404 is a high-severity vulnerability in yt-dlp and youtube-dl command-line audio/video downloaders. Prior to version 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping. This allows malicious file:// URI injection on Windows or [truncated]

HIGH yt-dlp CVE published 2026-06-23

CVE-2026-50574

CVE-2026-50574 is a high-severity vulnerability in yt-dlp, a command-line audio/video downloader. Prior to version 2026.06.09, when using aria2c as an external downloader for fragmented manifest formats like HLS/DASH streams, yt-dlp passes insufficiently sanitized input. This allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. O [truncated]

HIGH yt-dlp CVE published 2026-06-23

CVE-2026-50023

CVE-2026-50023 is a high-severity vulnerability in yt-dlp, a command-line audio/video downloader. Prior to version 2026.06.09, the vulnerability allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem. This is possible because the allowlist for the --write-link option included unsafe extensions like .desktop, .url, and .webloc. An attacker c [truncated]