← Vulnerability feed

Vulnerability record · CVE-2024-22423 · published 9 April 2024

CVE-2024-22423: Yt-dlp project yt-dlp os command injection vulnerability

Yt Dlp Project · Yt Dlp

yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion of environment variables. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2024.04.09 fixes this issue by properly escaping `%`. It replaces them with `%%cd:~,%`, a variable that expands to nothing, leaving only the leading percent. It is recommended to upgrade yt-dlp to version 2024.04.09 as soon as possible. Also, always be careful when using `--exec`, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade, avoid using any output template expansion in `--exec` other than `{}` (filepath); if expansion in `--exec` is needed, verify the fields you are using do not contain `"`, `|` or `&`; and/or instead of using `--exec`, write the info json and load the fields from it instead.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 31.7% CWE-78 · OS command injection
9.8CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion of environment variables. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2024.04.09 fixes this issue by properly escaping `%`. It replaces them with `%%cd:~,%`, a variable that expands to nothing, leaving only the leading percent. It is recommended to upgrade yt-dlp to version 2024.04.09 as soon as possible. Also, always be careful when using `--exec`, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade, avoid using any output template expansion in `--exec` other than `{}` (filepath); if expansion in `--exec` is needed, verify the fields you are using do not contain `"`, `|` or `&`; and/or instead of using `--exec`, write the info json and load the fields from it instead.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-3566Haskell process library command injection vulnerabilityA command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fu…EPSS 6.9%9.6CVE-2026-50023Yt-dlp project yt-dlp vulnerabilityyt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitra…EPSS 0.66%9.6CVE-2026-50574Yt-dlp project yt-dlp injection vulnerabilityyt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (s…EPSS 0.46%8.8CVE-2026-55404Yt-dlp project yt-dlp injection vulnerabilityyt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link optio…EPSS 0.64%8.8CVE-2026-26331Yt-dlp project yt-dlp os command injection vulnerabilityyt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-…EPSS 2.0%8.2CVE-2023-35934Youtube-dlc project youtube-dlc information exposure vulnerabilityyt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs m…EPSS 1.0%8.1CVE-2025-54072Yt-dlp project yt-dlp os command injection vulnerabilityyt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the de…EPSS 0.56%7.8CVE-2023-40581Yt-dlp project yt-dlp os command injection vulnerabilityyt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stage…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-22423), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.