Threat Advisory

yt-dlp Flaw Allows Arbitrary Command Injection via Downstream Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability (CVSS score: 7.5) exists in yt-dlp, allowing arbitrary command injection via downstream remote code execution due to the improper sanitization of yt-dlp's --write-link output. An attacker can craft a malicious metadata payload to achieve remote code execution on the user's system if the user executes the generated.url or.desktop files. This flaw is present in versions prior to 2026.7.4 and can be triggered through two known scenarios: file:// URI injection in Windows.url shortcut and shell command injection in Linux.desktop shortcut. The vulnerability allows for malicious shell commands or remote executables to run on the user's system, posing a significant business impact due to potential data breaches and system compromise. Users are advised to upgrade yt-dlp to version 2026.7.4 as soon as possible.

RECOMMENDATION:

We recommend you to update yt-dlp to version 2026.7.4.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability (CVSS score: 7.5) exists in yt-dlp, allowing arbitrary command injection via downstream remote code execution due to the improper sanitization of yt-dlp's --write-link output. An attacker can craft a malicious metadata payload to achieve remote code execution on the user's system if the user executes the generated.url or.desktop files. This flaw is present in versions prior to 2026.7.4 and can be triggered through two known scenarios: file:// URI injection in Windows.url shortcut and shell command injection in Linux.desktop shortcut. The vulnerability allows for malicious shell commands or remote executables to run on the user's system, posing a significant business impact due to potential data breaches and system compromise. Users are advised to upgrade yt-dlp to version 2026.7.4 as soon as possible.

RECOMMENDATION:

We recommend you to update yt-dlp to version 2026.7.4.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu