Aller au contenu

Fiche vulnérabilité

CVE-2025-54072 : faille élevée yt-dlp project yt-dlp (CVSS 8.1)

Description

yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the default placeholder (or {}), insufficient sanitization is applied to the expanded filepath, allowing for remote code execution. This is a bypass of the mitigation for CVE-2024-22423 where the default placeholder and {} were not covered by the new escaping rules. Windows users who are unable to upgrade should avoid using --exec altogether. Instead, the --write-info-json or --dump-json options could be used, with an external script or command line consuming the JSON output. This is fixed in version 2025.07.21.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • yt-dlp project yt-dlp

Références

Rechercher une autre vulnérabilité dans la base CVE