CRITICALPyPI →
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
Affected packages
- yt-dlp— before 2026.7.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.41%
- EPSS percentile
- 33.9%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 34%.
Sources
- https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
- https://nvd.nist.gov/vuln/detail/CVE-2026-55404
- https://github.com/yt-dlp/yt-dlp/commit/6fc85f617a5850307fd5b258477070e6ee177796
- https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789
- https://github.com/yt-dlp/yt-dlp
- https://github.com/yt-dlp/yt-dlp-nightly-builds/releases/tag/2026.07.04.221833
- https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04
Structured record: https://osv.dev/vulnerability/GHSA-6v4j-43gg-vj32
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta