← CVEs and Advisories

CVE-2026-50023

yt-dlp/yt-dlp · Severity High (CVSS 8.3) · Discovered by Pavan Nallamothu

A permission scoped to the --write-link feature was hoisted to a global extension allowlist. A subtitle track whose URI ended in .desktop caused yt-dlp to write an executable shortcut under --write-subs, turning untrusted metadata into a dangerous file write.

Summary

Dangerous file-type creation via a filename-sanitization bypass (executable-shortcut injection).

References

cve.org record · GitHub Security Advisory GHSA-c6mh-fpjc-4pr3