Security: yt-dlp/yt-dlp
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
yt-dlp: Downstream command injection via improper sanitization of --write-link outputGHSA-6v4j-43gg-vj32 published
Jul 4, 2026 by bashonlyHigh -
Arbitrary code execution in yt-dlp via manifest downloads with aria2cGHSA-vx4q-3cr2-7cg2 published
Jun 9, 2026 by Grub4KHigh -
File Downloader cookie leak with curl in yt-dlpGHSA-f7j3-774f-rfhj published
Jun 9, 2026 by Grub4KModerate -
Dangerous file type creation via insufficient filename sanitization in yt-dlp (Bypass of CVE-2024-38519)GHSA-c6mh-fpjc-4pr3 published
Jun 9, 2026 by Grub4KHigh -
Arbitrary command injection with the `--netrc-cmd` option in yt-dlpGHSA-g3gw-q23r-pgqm published
Feb 21, 2026 by Grub4KHigh -
Arbitrary command injection possible if --exec option used with yt-dlpGHSA-69qj-pvh9-c5wg published
Jun 9, 2026 by bashonlyHigh -
`--exec` command injection when using placeholder on Windows (Bypass of CVE-2024-22423)GHSA-45hg-7f49-5h56 published
Jul 21, 2025 by bashonlyHigh -
Dependency on potentially malicious third-party code in Douyu extractorsGHSA-3v33-3wmw-3785 published
Jul 7, 2024 by bashonlyLow -
File system modification and RCE through improper file-extension sanitizationGHSA-79w7-vh3h-8g4j published
Jul 1, 2024 by bashonlyHigh -
`--exec` command injection when using `%q` in yt-dlp on Windows (CVE-2023-40581 bypass)GHSA-hjq6-52gw-2g7p published
Apr 9, 2024 by Grub4KHigh
Learn more about advisories related to yt-dlp/yt-dlp in the GitHub Advisory Database