Skip to content
Vulnerabilities in yt-dlp Allow Remote Code Execution via Shortcut Files

Vulnerabilities in yt-dlp Allow Remote Code Execution via Shortcut Files

First seen 6 Oct 2026, 21:27 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 21:29 UTC
  • •Two critical vulnerabilities in yt-dlp allow remote code execution via shortcut files.
  • •Attackers can exploit crafted metadata to execute arbitrary commands on user systems.
  • •No patches are currently available; users should avoid specific yt-dlp options.

Two vulnerabilities in yt-dlp, identified as GHSA-6v4j-43gg-vj32 and GHSA-c6mh-fpjc-4pr3, enable remote attackers to exploit the software to create malicious OS-shortcut files (.url, .desktop, .webloc) on users' systems. The first vulnerability allows arbitrary command injection through crafted metadata payloads when using specific options, while the second bypasses a previous fix (CVE-2024-38519) that aimed to prevent unsafe file extensions. Attackers can leverage this flaw by manipulating media metadata, leading to the potential execution of malicious commands when users open these files. The vulnerabilities affect all versions of yt-dlp that support the affected options. Users are advised to avoid using the --write-link, --write-url-link, or --write-desktop-link options until a patch is released. As of now, no patches have been disclosed for these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-07-02
CVE-2024-38519 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
Vulnerabilities disclosed
GitHub disclosed two vulnerabilities in yt-dlp that allow remote code execution through malicious shortcut files.
Article 1
2026-10-06
Second vulnerability identified
A second vulnerability was disclosed that bypasses previous remediation efforts for CVE-2024-38519, allowing unsafe file extensions.
Article 2

More articles in this cluster (2)

Common questions

What versions of yt-dlp are affected?
All versions of yt-dlp that support the --write-link, --write-url-link, or --write-desktop-link options are affected.
Is there a patch available for these vulnerabilities?
No, as of now, no patches have been disclosed for these vulnerabilities.
What should users do to protect themselves?
Users should refrain from using the affected yt-dlp options until a patch is released.