Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
Vulnerability Description
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
yt-dlp 输入验证错误漏洞
Vulnerability Description
yt-dlp是yt-dlp团队的一个视频下载命令行工具。 yt-dlp 2026.06.09之前版本存在输入验证错误漏洞,该漏洞源于传递给aria2c的输入清理不足,可能导致攻击者进行任意文件写入,进而在Windows平台上立即执行任意代码,或在非Windows平台上在下次调用yt-dlp时执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A