chiprook
← Security
SecurityOctober 7, 2026, 02:26

yt-dlp RCE via .desktop files in HLS subtitles disclosed as CVE-2026-50023

A researcher detailed CVE-2026-50023 in yt-dlp: a global extension allowlist treated .desktop, .url and .webloc as peers of .srt. An HLS manifest with a subtitle URI ending in .desktop caused an executable shortcut to be written to the download folder. The fix shipped in version 2026.06.09.

yt-dlp RCE via .desktop files in HLS subtitles disclosed as CVE-2026-50023
#Yt-dlp
Read next
Policy

IFPI Wants yt-dlp on EU Piracy Watch List

Security

Hackers spoof US HR platforms with fake desktop apps to gain remote access

Security

Fake payroll desktop apps give attackers a route to company paychecks

Security

Codex Desktop flaw let untrusted code read auth tokens from shared memory