yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HYt Dlp Project Yt Dlp
APPYt-Dlp Project< 2026.07.04
Related vulnerabilities
Command injection w aplikacjach Windows korzystających z CreateProcess
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloa...
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that al...
yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.2...
yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exe...