Yt-dlp
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Yt-dlp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Yt-dlp CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 4 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High8
- Medium3
Latest CVEs
The 14 most recently published vulnerabilities affecting Yt-dlp.
- CVE-2026-55404yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output7.5
- CVE-2026-50019yt-dlp: File Downloader cookie leak with curl6.1
- CVE-2026-50574yt-dlp: Arbitrary code execution via manifest downloads with aria2c8.3
- CVE-2026-50023yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)8.3
- GHSA-69qj-pvh9-c5wgyt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp—
- CVE-2026-26331yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option8.8
- CVE-2025-54072yt-dlp allows `--exec` command injection when using placeholder on Windows7.5
- GHSA-3v33-3wmw-3785yt-dlp has dependency on potentially malicious third-party code in Douyu extractors—
- CVE-2024-38519yt-dlp and youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization7.8
- CVE-2024-3566Command injection vulnerability in programing languages on Microsoft Windows operating system.9.8
- CVE-2024-22423yt-dlp `--exec` command injection when using `%q` in yt-dlp on Windows8.3
- CVE-2023-46121Generic Extractor MITM Vulnerability in yt-dlp5.0
- CVE-2023-40581yt-dlp command injection when using `%q` in `--exec` on Windows8.3
- CVE-2023-35934yt-dlp File Downloader cookie leak6.1
Product grouping is registry-driven, with AI assist and human review. How it works