Junglewise Threat Intelligence

CVE-2024-38519: PYSEC-2026-2065 - yt-dlp File system modification and RCE through improper file-extension sanitization

CVE-2024-38519 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: yt-dlp (PyPI). Vendors: PyPI.

Executive brief

yt-dlp File system modification and RCE through improper file-extension sanitization

Affected products

  • PyPI yt-dlp

Related threats