<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:23:27.681241+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-gamdl-cve-2026-50574</id>
    <title>BREW-gamdl-CVE-2026-50574 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
    <updated>2026-10-04T08:23:27.688526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: gamdl</p>
<p>### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.</p>
<p>### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream's manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c's `-i` option.</p>
<p>aria2c's `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c's format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it's able to specify the output filename for each fragment using the `out=` option.</p>
<p>yt-dlp's utilization of the aria2c input file format presents two known attack vectors:</p>
<p>1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-gamdl-cve-2026-50574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330062</id>
    <title>EUVD-2026-330062</title>
    <updated>2026-10-04T08:23:27.688598+00:00</updated>
    <content>EUVD-2026-330062</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50574</id>
    <title>fkie_cve-2026-50574</title>
    <updated>2026-10-04T08:23:27.688615+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vx4q-3cr2-7cg2</id>
    <title>GHSA-vx4q-3cr2-7cg2 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
    <updated>2026-10-04T08:23:27.688639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: yt-dlp</p>
<p>### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.</p>
<p>### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream's manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c's `-i` option.</p>
<p>aria2c's `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c's format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it's able to specify the output filename for each fragment using the `out=` option.</p>
<p>yt-dlp's utilization of the aria2c input file format presents two known attack vectors:</p>
<p>1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vx4q-3cr2-7cg2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11019-1</id>
    <title>openSUSE-SU-2026:11019-1 — python313-yt-dlp-2026.06.09-1.1 on GA media</title>
    <updated>2026-10-04T08:23:27.688680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-yt-dlp-2026.06.09-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11019-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3433</id>
    <title>PYSEC-2026-3433 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
    <updated>2026-10-04T08:23:27.688698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: yt-dlp</p>
<p>### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.</p>
<p>### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream's manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c's `-i` option.</p>
<p>aria2c's `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c's format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it's able to specify the output filename for each fragment using the `out=` option.</p>
<p>yt-dlp's utilization of the aria2c input file format presents two known attack vectors:</p>
<p>1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50574</id>
    <title>UBUNTU-CVE-2026-50574</title>
    <updated>2026-10-04T08:23:27.688736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: yt-dlp, Ubuntu:24.04:LTS: yt-dlp, Ubuntu:25.10: yt-dlp, Ubuntu:26.04:LTS: yt-dlp</p>
<p>yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50574"/>
  </entry>
</feed>
