IA Squad
SearchPT
python · yt-dlpCritical

yt-dlp Vulnerability Allows Arbitrary Shortcut File Write (CVE-2024-38519 Bypass)

A vulnerability in yt-dlp allows remote attackers to write arbitrary OS-shortcut files (.

17 Jun 2026Read 1 minSeverity: act now

What changed

A vulnerability in yt-dlp allows remote attackers to write arbitrary OS-shortcut files (.desktop, .url, .webloc) to the user's filesystem, bypassing the fix for CVE-2024-38519. The fix in version 2026.06.09 removes these extensions from the global allowlist and restricts them to the --write-link option.

Who it affects

All users of yt-dlp who download media or subtitles, especially those using --write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, or --embed-thumbnail options.

What to do today

Upgrade yt-dlp to version 2026.06.09 immediately. If unable to upgrade, only pass trusted URLs and avoid using the listed options.

The trail
Collected Audited Written Published