Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c6mh-fpjc-4pr3 | yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) |
Thu, 25 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yt-dlp
Yt-dlp yt-dlp |
|
| Vendors & Products |
Yt-dlp
Yt-dlp yt-dlp |
Tue, 23 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions can be exploited by an attacker to write malicious OS-shortcut files in the context of a media or subtitles download. This vulnerability is fixed in 2026.06.09. | |
| Title | yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) | |
| Weaknesses | CWE-641 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-25T13:45:44.576Z
Reserved: 2026-06-02T22:46:02.579Z
Link: CVE-2026-50023
Updated: 2026-06-25T13:45:42.137Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T11:15:04Z
Github GHSA