Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.
FEDORA-2026-139d3aad5f (yt-dlp-2026.08.19-1.fc46) has been submitted as an update to Fedora 46. https://bodhi.fedoraproject.org/updates/FEDORA-2026-139d3aad5f
FEDORA-2026-c0410a0829 (yt-dlp-2026.08.19-1.fc45) has been submitted as an update to Fedora 45. https://bodhi.fedoraproject.org/updates/FEDORA-2026-c0410a0829
FEDORA-2026-139d3aad5f (yt-dlp-2026.08.19-1.fc46) has been pushed to the Fedora 46 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-c0410a0829 (yt-dlp-2026.08.19-1.fc45) has been pushed to the Fedora 45 stable repository. If problem still persists, please make note of it in this bug report.