CVE-2026-55404Patch(yt-dlp_project / yt-dlp)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yt-dlp_project yt-dlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yt-dlp

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-07-11); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
yt-dlp

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-07-11: 1Mentions · 2026-07-16: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-07-19: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-18: 107-1107-1607-1807-19
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-111
Patch1
2026-07-161
Patch1
2026-07-181
Patch1
2026-07-191
Disclosure1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-55404 yt-dlpおよびyoutube-dl(バージョン2026.7.4以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/16/cve-2026-55404-yt-dlpyoutube-dl202674/ #IT #Security #cybersecurity

    Post summary

    The post appears to be a disclosure article that explains CVE‑2026‑55404, summarizes its impact range, and provides countermeasures, but it does not share PoC, exploit code, or evidence of active exploitation.

    0000060
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-55404 yt-dlpおよびyoutube-dl(バージョン2026.7.4以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/16/cve-2026-55404-yt-dlpyoutube-dl202674/ #IT #Security #cybersecurity

    Post summary

    The article explains CVE‑2026‑55404, covering its technical details and offering patches or workarounds for yt‑dlp and youtube‑dl versions prior to 2026.7.4, while showing no evidence of active exploitation or a PoC.

    0000093
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-55404 yt-dlpおよびyoutube-dl(バージョン2026.7.4以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/16/cve-2026-55404-yt-dlpyoutube-dl202674/ #IT #Security #cybersecurity

    Post summary

    The article explains CVE‑2026‑55404 in yt‑dlp and youtube‑dl, outlines its impact scope, and summarizes mitigation measures, without mentioning active exploitation or a PoC.

    0000073
    207 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-55404 (CVSS 7.5) affects yt-dlp & youtube-dl. Malicious shortcut files can execute commands via file:// URI injection (Windows) or desktop entry injection (Linux). Update to v2026.7.4+ immediately. #CVE #PatchNow #ThreatIntel https://t.co/8Zhg2UgzT0

    Post summary

    The tweet alerts that CVE-2026-55404 allows command execution via malicious shortcut files in yt‑dlp and youtube‑dl; users are urged to update to version 2026.7.4 or newer.

    0000068
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyt-dlp_projectyt-dlp---

Explore more