Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q` High
CVE-2023-40581 was published for yt-dlp (pip) Sep 25, 2023
Grub4K Credited to Grub4K
yt-dlp File Downloader cookie leak Moderate
CVE-2023-35934 was published for yt-dlp (pip) Jul 6, 2023
Grub4K Credited to Grub4K, bashonly, and coletdjnz bashonly bashonly
coletdjnz coletdjnz
Ry0taK Credited to Ry0taK, Grub4K, and pukkandan Grub4K Grub4K
pukkandan pukkandan
yt-dlp File system modification and RCE through improper file-extension sanitization High
CVE-2024-38519 was published for yt-dlp (pip) Jul 2, 2024
pukkandan Credited to pukkandan, JarLob, and Grub4K JarLob JarLob
Grub4K Grub4K
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization High
GHSA-22fp-mf44-f2mq was published for youtube-dl (pip) Apr 18, 2025
pukkandan Credited to pukkandan, JarLob, Grub4K, dirkf, and rhdesmond JarLob JarLob
Grub4K Grub4K dirkf dirkf rhdesmond rhdesmond
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option High
CVE-2026-26331 was published for yt-dlp (pip) Feb 23, 2026
dxlerYT Credited to dxlerYT, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
ProTip! Advisories are also available from the GraphQL API