Yt-Dlp · Yt-Dlp · CVE-2026-55404
**Name of the Vulnerable Software and Affected Versions**
yt-dlp versions prior to 2026.07.04
**Description**
Improper sanitization of output when using the `--write-link` option allows for downstream command injection. This occurs because shortcut file data is not properly validated and sanitized before being processed.
**Recommendations**
Update yt-dlp to version 2026.07.04 or later.
As a temporary workaround, avoid using the `--write-link` option until the software is updated.