Vulnerabilidades en yt-dlp
11 resultadosAnálisis Vexday
O yt-dlp apresenta 11 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, indicando ritmo recente de descobertas. Nenhuma está sob exploração ativa (KEV) e não há críticas em termos de CVSS, reduzindo o risco imediato. A fraqueza dominante é injeção de comando (CWE-78), típica de ferramentas que processam entrada de usuário, exigindo validação cuidadosa em ambientes de risco.
CVE-2026-26331HIGHyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` optionEPSS 1.6%CVE-2023-40581HIGHyt-dlp command injection when using `%q` in `--exec` on WindowsEPSS 1.3%CVE-2024-22423HIGHyt-dlp `--exec` command injection when using `%q` in yt-dlp on WindowsEPSS 1.3%CVE-2023-35934MEDIUMyt-dlp File Downloader cookie leakEPSS 1.0%CVE-2026-50023HIGHyt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)EPSS 0.6%CVE-2025-54072HIGHyt-dlp allows `--exec` command injection when using placeholder on WindowsEPSS 0.6%CVE-2026-55404HIGHyt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link outputEPSS 0.4%CVE-2026-50574HIGHyt-dlp: Arbitrary code execution via manifest downloads with aria2cEPSS 0.4%CVE-2024-38519HIGHyt-dlp and youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitizationEPSS 0.3%CVE-2023-46121MEDIUMGeneric Extractor MITM Vulnerability in yt-dlpEPSS 0.3%CVE-2026-50019MEDIUMyt-dlp: File Downloader cookie leak with curlEPSS 0.3%