Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Gamer191

#17023of 56,326
16.9Total CVSS
Vulnerabilities · 2
High
2
PT-2026-55745
8.8
2026-07-04
Yt-Dlp · Yt-Dlp · CVE-2026-55404
**Name of the Vulnerable Software and Affected Versions** yt-dlp versions prior to 2026.07.04 **Description** Improper sanitization of output when using the `--write-link` option allows for downstream command injection. This occurs because shortcut file data is not properly validated and sanitized before being processed. **Recommendations** Update yt-dlp to version 2026.07.04 or later. As a temporary workaround, avoid using the `--write-link` option until the software is updated.
PT-2025-30264
8.1
2025-07-21
Yt-Dlp · Yt-Dlp · CVE-2025-54072
**Name of the Vulnerable Software and Affected Versions** yt-dlp versions 2025.06.25 and below eslint/plugin-kit version 0.3.3 and earlier **Description** yt-dlp is a command-line audio/video downloader vulnerable to remote code execution on Windows systems when the `--exec` option is used with the default placeholder or {}. This is due to insufficient sanitization of the expanded filepath. A previous mitigation for CVE-2024-22423 did not cover the default placeholder and {} expansion. Additionally, @eslint/plugin-kit is affected by a Regular Expression Denial of Service (ReDoS) vulnerability. **Recommendations** yt-dlp versions 2025.06.25 and below: Upgrade to version 2025.07.21 or later. eslint/plugin-kit versions 0.3.3 and earlier: Upgrade to version 0.3.3 or later.