CVE-2024-38519 — `yt-dlp` and `youtube-dl` are command-line audio/video downloaders
`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the download folder (and path traversal on Windows)
Published
2024-07-02T13:47:36.399Z
Last modified
2024-08-02T04:12:25.618Z
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
01What is this vulnerability?
`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the download folder (and path traversal on Windows). Since `yt-dlp` and `youtube-dl` also read config from the working directory (and on Windows executables will be…
02Affected products
| Vendor | Product | Versions |
|---|
| yt-dlp | yt | dlp — < 2024.07.01 |
| ytdl-org | youtube | dl — >= 2015.01.25, nightly |
03Active exploitation status
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
04Recommended remediation
- Patch to a fixed version listed in the vendor advisory (see references below).
- Mitigate with WAF rules, network egress filters, or feature flags where the patch is not yet available.
- Hunt historical logs for exploitation indicators — see Detection signatures below.
05Technical details
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
06Detection signatures
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
Open in Sigma generator →
07Related CVEs
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.
08Timeline
- Published: 2024-07-02T13:47:36.399Z
- Last modified: 2024-08-02T04:12:25.618Z
09References
- github.com — https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-79w7-vh3h-8g4j
- github.com — https://github.com/yt-dlp/yt-dlp/commit/5ce582448ececb8d9c30c8c31f58330090ced03a
- github.com — https://github.com/yt-dlp/yt-dlp/releases/tag/2024.07.01
- securitylab.github.com — https://securitylab.github.com/advisories/GHSL-2024-090_yt-dlp
- github.com — https://github.com/dirkf/youtube-dl/security/advisories/GHSA-22fp-mf44-f2mq
- securitylab.github.com — https://securitylab.github.com/advisories/GHSL-2024-089_youtube-dl/
- github.com — https://github.com/ytdl-org/youtube-dl/pull/32830
- github.com — https://github.com/ytdl-org/youtube-dl/commit/d42a222ed541b96649396ef00e19552aef…
Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →