Improper Restriction of Names for Files and Other Resources Affecting yt-dlp package, versions [,2026.6.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.62% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-YTDLP-17353911
  • published17 Jun 2026
  • disclosed16 Jun 2026
  • creditPavan Nallamothu

Introduced: 16 Jun 2026

CVE-2026-50023  (opens in a new tab)
CWE-641  (opens in a new tab)

How to fix?

Upgrade yt-dlp to version 2026.6.9 or higher.

Overview

yt-dlp is an A youtube-dl fork with additional features and patches

Affected versions of this package are vulnerable to Improper Restriction of Names for Files and Other Resources via insufficient sanitization of file extensions during the file download. An attacker can cause arbitrary OS-shortcut files to be written to the user's filesystem by supplying a crafted media playlist or subtitle URI, potentially leading to code execution or phishing attacks if the user opens the malicious file.

Note: This is only exploitable if the user passes options such as --write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, or --embed-thumbnail and downloads from untrusted sources.

Workaround

This vulnerability can be mitigated by only passing fully trusted input URLs, avoiding the use of the affected options, and interactively selecting download formats to validate file extensions.

CVSS Base Scores

version 4.0
version 3.1