Executive brief
youtube-dl is a command-line utility for downloading videos from streaming services. The tool fails to validate file extensions when saving downloaded media, allowing attackers to create files with arbitrary names and locations. On Windows systems, this can lead to remote code execution when malicious files are downloaded to directories that are part of the executable search path, or when files masquerade as configuration or executable files that youtube-dl or the operating system will automatically load and run.
Technical details
The vulnerability stems from improper file-extension sanitization (CWE-434: Unrestricted Upload of File with Dangerous Type, CWE-669: Incorrect Resource Transfer Between Spheres). youtube-dl does not restrict or validate output file extensions during the download process, allowing attackers to craft downloads with arbitrary extensions or include path traversal sequences. The attack requires user interaction (initiating a download from an attacker-controlled or compromised source) and local access to the target system. An attacker can exploit this to create executable files (e.g., .cmd, .bat, .exe on Windows) or configuration files in the download directory or via path traversal, leading to arbitrary code execution when these files are read by youtube-dl (which loads config from the working directory) or by Windows process searching (which includes the current directory by default). Patches available as of commit d42a222 and nightly builds tagged 2024-07-03 or later disable path separators and whitelist allowed extensions.
Affected products
- ytdl-org youtube-dl 2015.01.25 through 2021.12.17 and daily/nightly builds before 2024-07-03
Timeline
- 2024-07-01: disclosed: Related advisory GHSA-79w7-vh3h-8g4j published for yt-dlp
- 2025-04-18: disclosed: GHSA-22fp-mf44-f2mq advisory published for youtube-dl
- 2024-07-03: patched: Master commit d42a222 and nightly builds tagged 2024-07-03 or later contain remediation