PT-2026-48378 · Yt-Dlp+1 · Yt-Dlp+1
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
yt-dlp versions 2023.09.24 through 2026.06.08
Description
When
curl is used as an external downloader, cookies may be leaked to an unintended host during an HTTP redirect or when the host for download fragments differs from the parent manifest. This occurs because cookies passed via the --cookie parameter do not activate the cookie engine unless loaded from a file, causing curl to send cookies to domains or paths outside their intended scope. An attacker could exploit this by using a malicious website with a URL that triggers an unvalidated redirect—a situation where an application redirects a user to an external site without verifying the destination—sending sensitive cookie information to a server controlled by the attacker.Recommendations
Update to version 2026.06.09.
As a temporary workaround, do not use the
--downloader curl option.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Curl
Yt-Dlp