Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-50023— yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

Quick assessment

Affected
yt-dlp yt-dlp
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

yt-dlp是yt-dlp团队的一个视频下载命令行工具。 yt-dlp 2026.06.09之前版本存在路径遍历漏洞,该漏洞源于允许列表包含不安全的扩展名,可能导致远程攻击者在媒体或字幕下载环境下写入恶意的OS-shortcut文件。

CVSS 8.3 · High EPSS 0.66% · P50

Affected Version Matrix 1

VendorProduct Version RangeStatus
yt-dlp yt-dlp < 2026.06.09 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50023

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
Source: CVE Program / CVE List V5
Vulnerability Description
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions can be exploited by an attacker to write malicious OS-shortcut files in the context of a media or subtitles download. This vulnerability is fixed in 2026.06.09.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
文件和其他资源名称限制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
yt-dlp 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
yt-dlp是yt-dlp团队的一个视频下载命令行工具。 yt-dlp 2026.06.09之前版本存在路径遍历漏洞,该漏洞源于允许列表包含不安全的扩展名,可能导致远程攻击者在媒体或字幕下载环境下写入恶意的OS-shortcut文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
yt-dlp yt-dlp < 2026.06.09 -

II. Public POCs for CVE-2026-50023

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8844 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-50023

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-50023 (2)

Vendor Advisories for CVE-2026-50023 (1)

Vendor Pages for CVE-2026-50023 (1)

Same Patch Batch · yt-dlp · 2026-06-23 · 3 CVEs total

CVE-2026-50574 8.3 HIGH yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVE-2026-50019 6.1 MEDIUM yt-dlp: File Downloader cookie leak with curl

IV. Related Vulnerabilities

V. Comments for CVE-2026-50023

No comments yet


Leave a comment