Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242520
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3622
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
04 Aug
Fix available
Severity - 7.5 (High)
GHSA-6v4j-43gg-vj32
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
24 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-3433
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3430
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3431
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
13 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-3432
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
13 Jul
Fix available
Severity - 8.8 (High)
PYSEC-2026-2065
PyPI/yt-dlp
yt-dlp File system modification and RCE through improper file-extension sanitization
07 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2066
PyPI/yt-dlp
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2063
PyPI/yt-dlp
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
07 Jul
Fix available
Severity - 5.0 (Medium)
PYSEC-2026-2064
PyPI/yt-dlp
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2067
PyPI/yt-dlp
yt-dlp File Downloader cookie leak
07 Jul
Fix available
Severity - 6.1 (Medium)
GHSA-69qj-pvh9-c5wg
PyPI/yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
16 Jun
Fix available
Severity - 7.5 (High)
GHSA-vx4q-3cr2-7cg2
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-c6mh-fpjc-4pr3
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-f7j3-774f-rfhj
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
16 Jun
Fix available
Severity - 6.1 (Medium)
GHSA-g3gw-q23r-pgqm
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
23 Feb
Fix available
Severity - 8.8 (High)
Load more...
PyPI - OSV