Executive brief
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
Affected products
- PyPI yt-dlp
Junglewise Threat Intelligence
CVE-2023-40581 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: yt-dlp (PyPI). Vendors: PyPI.
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`