CVE-2026-55404

EUVD-2026-42368
yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.66%
Affected Products (NVD)
VendorProductVersion
yt-dlp_projectyt-dlp
𝑥
< 2026.07.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
yt-dlp
bookworm
vulnerable
forky
2026.07.04-1
fixed
sid
2026.08.19-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
youtube-dl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
yt-dlp
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage