CVE-2026-55404

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-08 20:16

Updated : 2026-07-13 17:01


NVD link : CVE-2026-55404

Mitre link : CVE-2026-55404

CVE.ORG link : CVE-2026-55404


JSON object : View

Products Affected

yt-dlp_project

  • yt-dlp
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')