Junglewise Threat Intelligence

CVE-2024-22423: PYSEC-2026-2066 - yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of )

CVE-2024-22423 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: yt-dlp (PyPI). Vendors: PyPI.

Executive brief

yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)

Affected products

  • PyPI yt-dlp

Related threats