Vulnerabilities in yt-dlp Allow Remote Code Execution via Shortcut Files
Article Content
- •Two critical vulnerabilities in yt-dlp allow remote code execution via shortcut files.
- •Attackers can exploit crafted metadata to execute arbitrary commands on user systems.
- •No patches are currently available; users should avoid specific yt-dlp options.
Two vulnerabilities in yt-dlp, identified as GHSA-6v4j-43gg-vj32 and GHSA-c6mh-fpjc-4pr3, enable remote attackers to exploit the software to create malicious OS-shortcut files (.url, .desktop, .webloc) on users' systems. The first vulnerability allows arbitrary command injection through crafted metadata payloads when using specific options, while the second bypasses a previous fix (CVE-2024-38519) that aimed to prevent unsafe file extensions. Attackers can leverage this flaw by manipulating media metadata, leading to the potential execution of malicious commands when users open these files. The vulnerabilities affect all versions of yt-dlp that support the affected options. Users are advised to avoid using the --write-link, --write-url-link, or --write-desktop-link options until a patch is released. As of now, no patches have been disclosed for these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What versions of yt-dlp are affected?
Is there a patch available for these vulnerabilities?
What should users do to protect themselves?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…