CVE-2026-55404

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*

History

13 Jul 2026, 17:01

Type Values Removed Values Added
First Time Yt-dlp Project yt-dlp
Yt-dlp Project
References () https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 - () https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 - Patch
References () https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04 - () https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04 - Product, Release Notes
References () https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32 - () https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*

08 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:16

Updated : 2026-07-13 17:01


NVD link : CVE-2026-55404

Mitre link : CVE-2026-55404

CVE.ORG link : CVE-2026-55404


JSON object : View

Products Affected

yt-dlp_project

  • yt-dlp
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')