PT-2026-48378 · Yt-Dlp+1 · Yt-Dlp+1

·

CVE-2026-50019

·

Published

2026-06-10

·

Updated

2026-07-13

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions yt-dlp versions 2023.09.24 through 2026.06.08
Description When curl is used as an external downloader, cookies may be leaked to an unintended host during an HTTP redirect or when the host for download fragments differs from the parent manifest. This occurs because cookies passed via the --cookie parameter do not activate the cookie engine unless loaded from a file, causing curl to send cookies to domains or paths outside their intended scope. An attacker could exploit this by using a malicious website with a URL that triggers an unvalidated redirect—a situation where an application redirects a user to an external site without verifying the destination—sending sensitive cookie information to a server controlled by the attacker.
Recommendations Update to version 2026.06.09. As a temporary workaround, do not use the --downloader curl option.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50019
GHSA-F7J3-774F-RFHJ
OPENSUSE-SU-2026:11019-1
OPENSUSE-SU-2026:21163-1
PYSEC-2026-3431

Affected Products

Curl
Yt-Dlp