Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-50574

около 2 месяцев назад

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2026-50574

около 2 месяцев назад

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2026-50574

около 2 месяцев назад

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, ...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-vx4q-3cr2-7cg2

около 2 месяцев назад

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21163-1

около 1 месяца назад

Security update for yt-dlp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, ...

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vx4q-3cr2-7cg2

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21163-1

Security update for yt-dlp

около 1 месяца назад

Уязвимостей на страницу