Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55404

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
EPSS Низкий

Описание

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*
Версия до 2026.07.04 (исключая)

EPSS

Процентиль: 34%
0.00412
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS3: 7.5
debian
около 1 месяца назад

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior ...

CVSS3: 7.5
github
14 дней назад

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

EPSS

Процентиль: 34%
0.00412
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-74