QID 995405

Date Published: 2023-09-26

QID 995405: Python (Pip) Security Update for yt-dlp (GHSA-42h4-v29r-42qg)

yt-dlp allows the user to provide shell commands to be executed at various stages in its download process through the --exec flag. This flag allows output template expansion in its argument, so that video metadata values may be used in the shell commands. The metadata fields can be combined with the %q conversion, which is intended to quote/escape these values so they can be safely passed to the shell.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-42h4-v29r-42qg for updates and patch information.
    Vendor References

    CVEs related to QID 995405

    Software Advisories
    Advisory ID Software Component Link
    GHSA-42h4-v29r-42qg yt-dlp URL Logo github.com/advisories/GHSA-42h4-v29r-42qg