CVE-2026-55404

HIGH

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

Title source: cna
STIX 2.1

Description

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (3)
pypi/yt-dlp 0 - 2026.7.4PyPI
yt-dlp/yt-dlp < 2026.7.4
yt-dlp_project/yt-dlp < 2026.07.04
Published Jul 08, 2026
Tracked Since Jul 09, 2026