CVE-2026-50023Patch(yt-dlp_project / yt-dlp)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yt-dlp_project yt-dlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions can be exploited by an attacker to write malicious OS-shortcut files in the context of a media or subtitles download. This vulnerability is fixed in 2026.06.09.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-641

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yt-dlp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
yt-dlp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Arbitrary OS shortcut file write via crafted media/subtitle extensions (CVE-2026-50023) yt-dlp is vulnerable to being tricked into writing attacker-chosen OS shortcut files (e.g., .desktop, .url, .webloc) to a user’s filesystem during downloads, affecting its filename/extension handling logic. The root cause is improper input validation/insufficient restrictions on output filename extensions, allowing a bypass of the earlier mitigation for CVE-2024-38519. An attacker exploits this by providing attacker-controlled media/subtitle extension sources (notably crafted m3u8 subtitle URIs) so that when the victim downloads content with yt-dlp, a malicious shortcut payload is written without needing elevated privileges. Impact includes planting phishing lures and persistence-like artifacts, with potential code execution or credential theft if the user later opens the generated shortcut file. 👉 Affected: yt-dlp < 2026.06.09 | Upgrade to 2026.06.09

    Post summary

    High severity vulnerability in yt-dlp allows arbitrary OS shortcut file writes via crafted media/subtitle URIs; users should upgrade to version 2026.06.09 to mitigate.

    0000071
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyt-dlp_projectyt-dlp---

Explore more