HIGH🇵🇱 Wersja polska

CVE-2026-55404

CVSS 7.5v3.1pub. 2026-07-08upd. 2026-07-13

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Yt Dlp Project Yt Dlp

    APP
    Yt-Dlp Project
    < 2026.07.04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-3566CRITICAL9.8PL ✓same product

Command injection w aplikacjach Windows korzystających z CreateProcess

CVE-2026-50574HIGH8.3same product

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloa...

CVE-2026-50023HIGH8.3same product

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that al...

CVE-2026-26331HIGH8.8same product

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.2...

CVE-2025-54072HIGH7.5same product

yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exe...