CVE-2026-50023
yt-dlp yt-dlp 취약점
- 대응 우선순위
- 점검
- CVSS
- 9.6
- EPSS
- 0.56% 백분위 42.1% · 2026.06.27 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.24
CVSS 위험도가 높아 영향 여부를 우선 점검할 취약점
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the unsafe extensions .desktop, .url, and .webloc so that the functionality of the --write-link option (and its variants) could be preserved. These allowlist inclusions can be exploited by an attacker to write malicious OS-shortcut files in the context of a media or subtitles download....
공급사 yt-dlp
제품 yt-dlp
영향 버전 < 2026.06.09
수정 버전 2026.06.09
CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE CWE-641
EPSS 데이터 기준일 2026.06.27