Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3622
  • PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output 04 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-6v4j-43gg-vj32
  • PyPI/yt-dlp
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output 24 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3433
  • PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c 13 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-3430
  • PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) 13 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-3431
  • PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl 13 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-3432
  • PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option 13 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-2065
  • PyPI/yt-dlp
yt-dlp File system modification and RCE through improper file-extension sanitization 07 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-2066
  • PyPI/yt-dlp
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581) 07 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-2063
  • PyPI/yt-dlp
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection 07 Jul
  • Fix available
  • Severity - 5.0 (Medium)
PYSEC-2026-2064
  • PyPI/yt-dlp
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q` 07 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-2067
  • PyPI/yt-dlp
yt-dlp File Downloader cookie leak 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-69qj-pvh9-c5wg
  • PyPI/yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp 16 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-vx4q-3cr2-7cg2
  • PyPI/yt-dlp
yt-dlp: Arbitrary code execution via manifest downloads with aria2c 16 Jun
  • Fix available
  • Severity - 8.3 (High)
GHSA-c6mh-fpjc-4pr3
  • PyPI/yt-dlp
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) 16 Jun
  • Fix available
  • Severity - 8.3 (High)
GHSA-f7j3-774f-rfhj
  • PyPI/yt-dlp
yt-dlp: File Downloader cookie leak with curl 16 Jun
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-g3gw-q23r-pgqm
  • PyPI/yt-dlp
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option 23 Feb
  • Fix available
  • Severity - 8.8 (High)