<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:23:05 +0000</lastBuildDate>
    <item>
      <title>BREW-gamdl-CVE-2026-50574 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
      <link>https://cve.radiocsirt.org/vuln/brew-gamdl-cve-2026-50574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gamdl&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gamdl&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-gamdl-cve-2026-50574</guid>
    </item>
    <item>
      <title>EUVD-2026-330062</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330062</link>
      <description>EUVD-2026-330062</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330062</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50574</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50574</link>
      <description>&lt;p&gt;yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50574</guid>
    </item>
    <item>
      <title>GHSA-vx4q-3cr2-7cg2 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vx4q-3cr2-7cg2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: yt-dlp&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: yt-dlp&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vx4q-3cr2-7cg2</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11019-1 — python313-yt-dlp-2026.06.09-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11019-1</link>
      <description>&lt;p&gt;python313-yt-dlp-2026.06.09-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-yt-dlp-2026.06.09-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11019-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3433 — yt-dlp: Arbitrary code execution via manifest downloads with aria2c</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3433</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: yt-dlp&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: yt-dlp&lt;/p&gt;
&lt;p&gt;### Summary
If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp.&lt;/p&gt;
&lt;p&gt;### Details
When downloading a fragmented manifest format such as an HLS or DASH stream, yt-dlp first extracts a list of all fragment URLs from the stream&amp;#39;s manifest. If the user has selected aria2c as an external downloader, yt-dlp then constructs an input file for aria2c from the fragment URL list and passes its filepath as the argument to aria2c&amp;#39;s `-i` option.&lt;/p&gt;
&lt;p&gt;aria2c&amp;#39;s `-i` (or `--input-file`) option allows for downloading a list of URIs from the given text file. The text file must be formatted as a list of URIs separated by newlines. aria2c&amp;#39;s format permits configuration lines for each URI, which can contain command-line options to be given to aria2c. These optional lines follow each URI line and are signified only by leading whitespace. yt-dlp constructs the input file with these optional lines so that it&amp;#39;s able to specify the output filename for each fragment using the `out=` option.&lt;/p&gt;
&lt;p&gt;yt-dlp&amp;#39;s utilization of the aria2c input file format presents two known attack vectors:&lt;/p&gt;
&lt;p&gt;1. An attacker can craft a malicious DASH manifest with one or more fragment URLs that cont…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3433</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50574</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: yt-dlp, Ubuntu:24.04:LTS: yt-dlp, Ubuntu:25.10: yt-dlp, Ubuntu:26.04:LTS: yt-dlp&lt;/p&gt;
&lt;p&gt;yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: yt-dlp, Ubuntu:24.04:LTS: yt-dlp, Ubuntu:25.10: yt-dlp, Ubuntu:26.04:LTS: yt-dlp&lt;/p&gt;
&lt;p&gt;yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this can lead to immediate arbitrary code execution. On non-Windows platforms, this can lead to arbitrary code execution upon the next invocation of yt-dlp. This vulnerability is fixed in 2026.06.09.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50574</guid>
    </item>
  </channel>
</rss>
