Executive brief
yt-dlp is a popular command-line tool used to download audio and video from various websites. A security flaw allows a remote attacker to trick the tool into creating malicious shortcut files on a user's computer during a download. If a user opens these files, it could lead to unauthorized actions or full system compromise.
Technical details
A vulnerability in yt-dlp (CWE-641) allows for improper restriction of file names, enabling a remote attacker to write arbitrary OS-shortcut files (.desktop, .url, .webloc) to a user's filesystem. This issue stems from an overly permissive allowlist that included these extensions to maintain '--write-link' functionality, effectively bypassing previous fixes for CVE-2024-38519. An attacker can exploit this by providing malicious metadata in the context of a media or subtitles download. Successful exploitation requires user interaction to trigger the download and subsequently open the malicious shortcut. The vulnerability is addressed in version 2026.06.09 by restricting these extensions specifically to the '--write-link' feature.
Affected products
- yt-dlp yt-dlp < 2026.06.09
Timeline
- 2026-06-09: patched: Fixed in version 2026.06.09
- 2026-06-23: advisory: NVD publication date