CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

CVE-2026-55404Published 1 week agoUpdated 1 day agoSource: OSV

Affected packages

  • yt-dlpbefore 2026.7.4

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.41%
EPSS percentile
33.9%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 34%.

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output | HackTribune