Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
Vulnerability Description
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions can be exploited by an attacker to write malicious OS-shortcut files in the context of a media or subtitles download. This vulnerability is fixed in 2026.06.09.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
文件和其他资源名称限制不恰当
Vulnerability Title
yt-dlp 路径遍历漏洞
Vulnerability Description
yt-dlp是yt-dlp团队的一个视频下载命令行工具。 yt-dlp 2026.06.09之前版本存在路径遍历漏洞,该漏洞源于允许列表包含不安全的扩展名,可能导致远程攻击者在媒体或字幕下载环境下写入恶意的OS-shortcut文件。
CVSS Information
N/A
Vulnerability Type
N/A