CVE-2026-55404
HIGHyt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
Title source: cnaDescription
yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
X_Refsource_Misc x_refsource_misc
https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789
X_Refsource_Misc x_refsource_misc
https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
33.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-74
Status
published
Products (3)
pypi/yt-dlp
0 - 2026.7.4PyPI
yt-dlp/yt-dlp
< 2026.7.4
yt-dlp_project/yt-dlp
< 2026.07.04
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026