Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-55404

около 1 месяца назад

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-55404

около 1 месяца назад

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-55404

около 1 месяца назад

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6v4j-43gg-vj32

14 дней назад

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55404

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-55404

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-55404

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-6v4j-43gg-vj32

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

CVSS3: 7.5
0%
Низкий
14 дней назад

Уязвимостей на страницу