Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

yt-dlp — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting yt-dlp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

yt-dlp serves as a command-line tool for downloading videos from YouTube and other platforms, enabling media extraction and archival. Historically, it has been susceptible to multiple remote code execution vulnerabilities due to insecure subprocess handling and improper input validation, along with cross-site scripting issues through malicious URLs. The tool's nature of executing external commands and parsing untrusted input makes it prone to privilege escalation when run with elevated permissions. While no major public security incidents have been widely documented, its seven CVE records highlight consistent risks in handling malformed URLs and external dependencies, requiring careful sandboxing and input sanitization in deployment environments.

Top products by yt-dlp: yt-dlp

This page lists every published CVE security advisory associated with yt-dlp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.