Vendorsyt-dlp Projectyt-dlpany version
Vulnerabilities

yt-dlp Project yt-dlp any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-3566
Command injection vulnerability in programing languages on Microsoft Windows operating system.
Published 2024-04-10 · Analyzed
9.8EPSS 0.069
CVE-2024-22423
yt-dlp `--exec` command injection when using `%q` in yt-dlp on Windows
Published 2024-04-09 · Analyzed
9.8EPSS 0.013
CVE-2026-50023
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
Published 2026-06-23 · Analyzed
9.6EPSS 0.007
CVE-2026-50574
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
Published 2026-06-23 · Analyzed
9.6EPSS 0.005
CVE-2026-26331
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
Published 2026-02-24 · Analyzed
8.8EPSS 0.020
CVE-2026-55404
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
Published 2026-07-08 · Analyzed
8.8EPSS 0.006
CVE-2023-40581
yt-dlp command injection when using `%q` in `--exec` on Windows
Published 2023-09-25 · Modified
8.3EPSS 0.013
CVE-2023-35934
yt-dlp File Downloader cookie leak
Published 2023-07-06 · Modified
8.2EPSS 0.010
CVE-2025-54072
yt-dlp allows `--exec` command injection when using placeholder on Windows
Published 2025-07-22 · Analyzed
8.1EPSS 0.006
CVE-2026-50019
yt-dlp: File Downloader cookie leak with curl
Published 2026-06-23 · Analyzed
7.4EPSS 0.003
CVE-2023-46121
Generic Extractor MITM Vulnerability in yt-dlp
Published 2023-11-14 · Modified
5.0EPSS 0.003