Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2220440
AlmaLinux
5946
Alpaquita
16105
Alpine
4618
Android
3677
Azure Linux
17673
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1035748
CleanStart
4478
CRAN
14
crates.io
2745
Debian
68687
Echo
7558
GHC
3
GIT
108602
GitHub Actions
55
Go
9247
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7046
MinimOS
146748
npm
229024
NuGet
1869
opam
29
openEuler
8900
openSUSE
14498
OSS-Fuzz
4014
Packagist
7100
Pub
11
PyPI
25233
Red Hat
23413
Rocky Linux
4321
Root
19609
RubyGems
5326
SUSE
23390
SwiftURL
60
TuxCare
9675
Ubuntu
65801
VSCode
21
Wolfi
290799
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3622
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
04 Aug
Fix available
Severity - 7.5 (High)
GHSA-6v4j-43gg-vj32
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
24 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-3433
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3430
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3431
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
13 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-3432
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
13 Jul
Fix available
Severity - 8.8 (High)
PYSEC-2026-2065
PyPI/yt-dlp
yt-dlp File system modification and RCE through improper file-extension sanitization
07 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2066
PyPI/yt-dlp
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2063
PyPI/yt-dlp
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
07 Jul
Fix available
Severity - 5.0 (Medium)
PYSEC-2026-2064
PyPI/yt-dlp
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2067
PyPI/yt-dlp
yt-dlp File Downloader cookie leak
07 Jul
Fix available
Severity - 6.1 (Medium)
GHSA-69qj-pvh9-c5wg
PyPI/yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
16 Jun
Fix available
Severity - 7.5 (High)
GHSA-vx4q-3cr2-7cg2
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-c6mh-fpjc-4pr3
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-f7j3-774f-rfhj
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
16 Jun
Fix available
Severity - 6.1 (Medium)
GHSA-g3gw-q23r-pgqm
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
23 Feb
Fix available
Severity - 8.8 (High)
Load more...
PyPI - OSV