Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affecting yt-dlp package, versions [,2026.6.9)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.41% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-YTDLP-17353925
  • published17 Jun 2026
  • disclosed16 Jun 2026
  • creditsepro

Introduced: 16 Jun 2026

CVE-2026-50574  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

Upgrade yt-dlp to version 2026.6.9 or higher.

Overview

yt-dlp is an A youtube-dl fork with additional features and patches

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via insufficient sanitization of input passed to the aria2c external downloader. An attacker can achieve arbitrary file writes and potentially execute code by crafting malicious manifest files or metadata that inject options or URIs into the aria2c input file. This can result in immediate code execution on Windows platforms or on subsequent runs on other platforms.

Note: This is only exploitable if aria2c is used as an external downloader for fragmented manifest formats, or if the user disables filename sanitization with the --no-windows-filename option.

Workaround

This vulnerability can be mitigated by adding --downloader dash,m3u8:native to the yt-dlp command.

CVSS Base Scores

version 4.0
version 3.1