A permission scoped to the --write-link feature was hoisted to a global extension allowlist. A subtitle track whose URI ended in .desktop caused yt-dlp to write an executable shortcut under --write-subs, turning untrusted metadata into a dangerous file write.
Dangerous file-type creation via a filename-sanitization bypass (executable-shortcut injection).
cve.org record · GitHub Security Advisory GHSA-c6mh-fpjc-4pr3