VYPR

Yt Dlp

by Yt Dlp

Source repositories

CVEs (3)

  • CVE-2026-50574higJun 16, 2026
    risk 0.38cvss epss

    ### Summary If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to…

  • CVE-2026-50023higJun 16, 2026
    risk 0.38cvss epss

    ### Summary A vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as `.desktop`, `.url`, `.webloc`) to the user's filesystem, bypassing the remediation for `CVE-2024-38519`. ### Details The fix for `CVE-2024-38519` enforced…

  • CVE-2026-50019Jun 16, 2026
    risk 0.00cvss epss

    ### Summary If curl is used an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. This is the equivalent to [GHSA-v8mc-9377-rwjj](<https://github.com/yt-dlp/…