pypi package report

Is yt-dlp safe?

12 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
4.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-6v4j-43gg-vj32, the advisory selected below

// advisories

GHSA-6v4j-43gg-vj32

HIGHCVE-2026-55404

If the --write-link, --write-url-link or --write-desktop-link options are used with yt-dlp, it may produce output that can lead to downstream remote code execution. An attacker can craft a malicious metadata payload to achieve arbitrary command injection in the .url and .desktop shortcut files written by yt-dlp. This allows for malicious shell commands or malicious remote executables to run on the

Affected
< 2026.7.4
Fixed in
2026.7.4
Weakness
CWE-74
Published
2026-07-24
Source
github

GHSANVDMITREreferencereferencereferencereferencereference


// dependencies

34 direct, 17 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 00:48 UTC. The most recent advisory here was published 2026-07-24. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is yt-dlp safe? pypi package security report | CyberXYZ