Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2199719
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9292
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2734
Debian
68378
Echo
7422
GHC
3
GIT
108138
GitHub Actions
55
Go
9203
Hackage
32
Hex
364
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144419
npm
228744
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25171
Red Hat
23355
Rocky Linux
4298
Root
19553
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9512
Ubuntu
65374
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3622
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
04 Aug
Fix available
Severity - 7.5 (High)
GHSA-6v4j-43gg-vj32
PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
24 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-3433
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3430
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-3431
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
13 Jul
Fix available
Severity - 6.1 (Medium)
PYSEC-2026-3432
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
13 Jul
Fix available
Severity - 8.8 (High)
PYSEC-2026-2065
PyPI/yt-dlp
yt-dlp File system modification and RCE through improper file-extension sanitization
07 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-2066
PyPI/yt-dlp
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2063
PyPI/yt-dlp
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
07 Jul
Fix available
Severity - 5.0 (Medium)
PYSEC-2026-2064
PyPI/yt-dlp
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
07 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2067
PyPI/yt-dlp
yt-dlp File Downloader cookie leak
07 Jul
Fix available
Severity - 6.1 (Medium)
GHSA-69qj-pvh9-c5wg
PyPI/yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
16 Jun
Fix available
Severity - 7.5 (High)
GHSA-vx4q-3cr2-7cg2
PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-c6mh-fpjc-4pr3
PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
16 Jun
Fix available
Severity - 8.3 (High)
GHSA-f7j3-774f-rfhj
PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl
16 Jun
Fix available
Severity - 6.1 (Medium)
GHSA-g3gw-q23r-pgqm
PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
23 Feb
Fix available
Severity - 8.8 (High)
Load more...
PyPI - OSV