yt-dlp
A feature-rich command-line audio/video downloader
Activity
- Latest release
- 2w ago
- Total releases
- 638
- Cadence
- ~daily
- Last 12 months
- 155
Reach
- Stars
- 188.7k
Details
- License
- Unlicense
- First release
- Jan 15, 2021
| Version | Released | |
|---|---|---|
2026.8.30.232658.dev0
pre
| ||
2026.8.29.232711.dev0
pre
| ||
2026.8.27.231323.dev0
pre
| ||
2026.8.27.3630.dev0
pre
| ||
2026.8.25.233329.dev0
pre
| ||
2026.8.20.234504.dev0
pre
| ||
2026.8.19
minor
| ||
2026.8.19.233000.dev0
pre
| ||
2026.8.18.122307.dev0
pre
| ||
2026.8.17.73947.dev0
pre
| ||
2026.8.16.20253.dev0
pre
| ||
2026.8.4.234419.dev0
pre
| ||
2026.7.23.234303.dev0
pre
|
2026.7.23.234303.dev0
pre
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
2026.7.21.234255.dev0
pre
| ||
2026.7.20.234742.dev0
pre
| ||
2026.7.14.233956.dev0
pre
| ||
2026.7.12.233956.dev0
pre
| ||
2026.7.9.234832.dev0
pre
| ||
2026.7.6.234510.dev0
pre
| ||
2026.7.4
minor
| ||
2026.7.4.221833.dev0
pre
| ||
2026.7.3.234421.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.7.2.234458.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.7.1.235203.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.30.234726.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.29.234344.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.28.234618.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.27.234340.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.26.234622.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.24.234707.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.21.235142.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.20.234736.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.18.235958.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.17.235412.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.16.235352.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.16.106.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.13.234541.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.12.235626.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.11.235628.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.10.235405.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.9
minor
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.9.230517.dev0
pre
1 CVE
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.6.6.234447.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.5.25.234532.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.5.24.234402.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.5.16.233954.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.5.5.233942.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.5.3.233852.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.4.30.234007.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
| ||
2026.4.10.235301.dev0
pre
5 CVEs
CVE-2026-55404
PYSEC-2026-3622
GHSA-6v4j-43gg-vj32
Aug 04, 2026
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
SummaryIf the DetailsThe expected result of yt-dlp's There are two known scenarios where a remote attacker could serve a malicious metadata payload to exploit yt-dlp's improper validation/sanitization of its shortcut output and achieve arbitrary code execution if the user later opens these files. Scenario 1:
|