© 2025-2026 PySpect
First version without a known vulnerability: 2026.7.4.221833.dev0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
Fixed in: 2026.7.4
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
Fixed in: 2026.6.9
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
Fixed in: 2026.6.9
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
Fixed in: 2026.6.9
yt-dlp: File Downloader cookie leak with curl
Fixed in: 2026.6.9
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
Fixed in: 2026.02.21
yt-dlp has dependency on potentially malicious third-party code in Douyu extractors
Fixed in: 2024.07.07
yt-dlp File system modification and RCE through improper file-extension sanitization
Fixed in: 2024.07.01
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
Fixed in: 2024.04.09
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
Fixed in: 2023.11.14
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
Fixed in: 2023.09.24
yt-dlp File Downloader cookie leak
Fixed in: 2023.7.06