GHSA-6v4j-43gg-vj32
HIGHCVE-2026-55404If the --write-link, --write-url-link or --write-desktop-link options are used with yt-dlp, it may produce output that can lead to downstream remote code execution. An attacker can craft a malicious metadata payload to achieve arbitrary command injection in the .url and .desktop shortcut files written by yt-dlp. This allows for malicious shell commands or malicious remote executables to run on the
- Affected
- < 2026.7.4
- Fixed in
- 2026.7.4
- Weakness
- CWE-74
- Published
- 2026-07-24
- Source
- github