VDB
CVE-2026-55404
CVE-2026-55404
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 8, 2026
yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| yt-dlp | yt-dlp | < 2026.7.4 |
| yt-dlp | yt-dlp | < 2026.7.4, < 2026.7.4 |
Timeline
- Jul 6, 2026 CVE Published
- Jul 9, 2026 EPSS Score
- Jul 9, 2026 Coalition ESS Score
- Aug 4, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 8, 2026 Security Advisory
References
- https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32 x_refsource_CONFIRM
- https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 x_refsource_MISC
- https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04 x_refsource_MISC