Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp High
GHSA-69qj-pvh9-c5wg was published for yt-dlp (pip) Jun 16, 2026
independent-arg Credited to independent-arg, bashonly, and Grub4K bashonly bashonly
Grub4K Grub4K
yt-dlp: Arbitrary code execution via manifest downloads with aria2c High
CVE-2026-50574 was published for yt-dlp (pip) Jun 16, 2026
seproDev Credited to seproDev, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
pavanchow Credited to pavanchow, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
yt-dlp: File Downloader cookie leak with curl Moderate
CVE-2026-50019 was published for yt-dlp (pip) Jun 16, 2026
seproDev Credited to seproDev, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option High
CVE-2026-26331 was published for yt-dlp (pip) Feb 23, 2026
dxlerYT Credited to dxlerYT, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
yt-dlp has dependency on potentially malicious third-party code in Douyu extractors Low
GHSA-3v33-3wmw-3785 was published for yt-dlp (pip) Jul 8, 2024
LeSuisse Credited to LeSuisse and bashonly bashonly bashonly
yt-dlp File Downloader cookie leak Moderate
CVE-2023-35934 was published for yt-dlp (pip) Jul 6, 2023
Grub4K Credited to Grub4K, bashonly, and coletdjnz bashonly bashonly
coletdjnz coletdjnz
ProTip! Advisories are also available from the GraphQL API