VDB

GCVE-110-MAGEIA-2026-234

GCVE-110-MAGEIA-2026-234
Advisory Published
Vulnetix · Advisory published July 4, 2026
CVE-2026-50019 If curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. CVE-2026-50023 A vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. CVE-2026-50574 If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. For mageia 9 we import yt-dlp-ejs to ensure the application still works.

Affected Products

VendorProductVersionsPlatforms
Mageiayt-dlp-ejs0 (affected), 0.8.0-1.mga9 (unaffected)
Mageiayt-dlp0 (affected), 2026.06.09-1.mga10 (unaffected)
Mageiayt-dlp0 (affected), 2026.06.09-1.1.mga9 (unaffected)

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›