Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vx4q-3cr2-7cg2 | yt-dlp: Arbitrary code execution via manifest downloads with aria2c |
Tue, 23 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yt-dlp
Yt-dlp yt-dlp |
|
| Vendors & Products |
Yt-dlp
Yt-dlp yt-dlp |
Tue, 23 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09. | |
| Title | yt-dlp: Arbitrary code execution via manifest downloads with aria2c | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-25T03:55:47.470Z
Reserved: 2026-06-04T21:34:34.427Z
Link: CVE-2026-50574
Updated: 2026-06-23T16:59:45.686Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T11:15:04Z
Github GHSA