Executive brief
yt-dlp is a popular command-line tool used to download video and audio from various websites. A vulnerability exists when the tool uses the 'aria2c' external downloader to process certain media streams, allowing a malicious website or manifest file to trick the tool into writing files to the user's computer. This can lead to the attacker taking full control of the system by placing malicious executable files in the tool's working directory.
Technical details
A vulnerability in yt-dlp (CWE-74) arises when using aria2c as an external downloader for fragmented manifest formats like HLS or DASH. yt-dlp constructs an input file for aria2c's '-i' option but fails to properly sanitize newlines and HTML escape sequences (e.g., ) in fragment URLs or metadata fields. An attacker can craft a malicious DASH manifest or metadata response to inject arbitrary aria2c options, such as 'out=', enabling arbitrary file writes. On Windows, this can lead to immediate RCE by overwriting binaries like ffmpeg.exe in the working directory; on other platforms, RCE can be achieved by writing a malicious yt-dlp.conf file. The issue is fixed in version 2026.06.09 by removing support for downloading fragmented manifests via aria2c.
Affected products
- yt-dlp yt-dlp < 2026.06.09
Timeline
- 2026-06-09: patched: Vulnerability fixed in version 2026.06.09
- 2026-06-23: advisory: NVD and GitHub advisories published