2026.8.4.234419.dev0
5 years ago
9 days ago
Known vulnerabilities in the yt-dlp package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
yt-dlp is an A youtube-dl fork with additional features and patches Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via improper validation of input in the How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,2026.7.4) |
yt-dlp is an A youtube-dl fork with additional features and patches Affected versions of this package are vulnerable to Command Injection via Note: This is only expoitable when users pass an How to fix Command Injection? Upgrade | [2021.4.11,2026.6.9) |
yt-dlp is an A youtube-dl fork with additional features and patches Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via insufficient sanitization of input passed to the Note: This is only exploitable if How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,2026.6.9) |
yt-dlp is an A youtube-dl fork with additional features and patches Affected versions of this package are vulnerable to Improper Restriction of Names for Files and Other Resources via insufficient sanitization of file extensions during the file download. An attacker can cause arbitrary OS-shortcut files to be written to the user's filesystem by supplying a crafted media playlist or subtitle URI, potentially leading to code execution or phishing attacks if the user opens the malicious file. Note: This is only exploitable if the user passes options such as How to fix Improper Restriction of Names for Files and Other Resources? Upgrade | [,2026.6.9) |
yt-dlp is an A youtube-dl fork with additional features and patches Affected versions of this package are vulnerable to Reliance on Cookies without Validation and Integrity Checking via How to fix Reliance on Cookies without Validation and Integrity Checking? Upgrade | [2023.9.24,2026.6.9) |