PT-2026-48379 · Yt-Dlp · Yt-Dlp
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
yt-dlp versions prior to 2026.06.09
Description
A flaw allows a remote attacker to write arbitrary OS-shortcut files, such as
.desktop, .url, and .webloc, to the user's filesystem. This occurs because the file extension allowlist used to prevent unsafe downloads explicitly included these shortcut extensions to maintain the functionality of the --write-link option. Attackers can exploit this by crafting a malicious m3u8 file containing an EXT-X-MEDIA:TYPE=SUBTITLES tag with a malicious URI. If a user employs the --write-subs option, the software may write attacker-controlled content to a file with a shortcut extension. These files can contain shell commands or point to remote executables, enabling phishing attacks or arbitrary code execution if a user is deceived into opening them.Recommendations
Update yt-dlp to version 2026.06.09.
As a temporary workaround, only provide fully trusted input URLs to the software.
As a temporary workaround, avoid using the
--write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, or --embed-thumbnail options.
As a temporary workaround, use --format - to interactively select download formats and validate their file extensions.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yt-Dlp