yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
References
| Link | Resource |
|---|---|
| https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 | Patch |
| https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04 | Product Release Notes |
| https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32 | Mitigation Vendor Advisory |
Configurations
History
13 Jul 2026, 17:01
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Yt-dlp Project yt-dlp
Yt-dlp Project |
|
| References | () https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 - Patch | |
| References | () https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04 - Product, Release Notes | |
| References | () https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32 - Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:* |
08 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 20:16
Updated : 2026-07-13 17:01
NVD link : CVE-2026-55404
Mitre link : CVE-2026-55404
CVE.ORG link : CVE-2026-55404
JSON object : View
Products Affected
yt-dlp_project
- yt-dlp
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
