Moodle dl: yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) (CVE-2026-50023)
A vulnerability in yt-dlp allows remote attackers to write arbitrary OS-shortcut files (.desktop, .url, .webloc) to the user's filesystem by bypassing the previous fix for CVE-2024-38519. This occurs because the allowlist for file extensions included unsafe shortcut file types to preserve functionality, which attackers can exploit via crafted media manifests. The malicious shortcut files can be disguised as subtitle or media files, potentially leading to social engineering attacks or arbitrary code execution. The issue is fixed in yt-dlp version 2026.06.09 by removing these extensions from the global allowlist except within the intended context. Users are advised to upgrade or apply strict usage restrictions if unable to update.
AI Analysis
Technical Summary
The yt-dlp tool had a vulnerability (CVE-2026-50023) that allowed attackers to write arbitrary OS-shortcut files such as .desktop, .url, and .webloc by exploiting the inclusion of these extensions in the file extension allowlist intended for the --write-link option. Attackers can craft malicious m3u8 manifests with subtitle URIs pointing to files with these extensions, causing yt-dlp to write malicious shortcut files when options like --write-subs are used. These shortcut files can execute shell commands or point to remote executables, posing a risk of social engineering and code execution. The vulnerability bypasses the previous fix for CVE-2024-38519. The issue is resolved in yt-dlp version 2026.06.09 by restricting these extensions to the --write-link context only.
Potential Impact
Successful exploitation allows remote attackers to write malicious OS-shortcut files to the user's filesystem, which can be disguised as subtitle or media files. Because shortcut file extensions are often hidden, users may be tricked into executing malicious shortcuts, leading to phishing attacks or arbitrary code execution. The vulnerability has a high impact on confidentiality, integrity, and availability as indicated by a CVSS score of 8.3.
Mitigation Recommendations
A patch is available in yt-dlp version 2026.06.09 that removes .desktop, .url, and .webloc from the global file extension allowlist and restricts their use to the --write-link option context. Users should upgrade to this version immediately. If upgrading is not possible, users must only pass fully trusted URLs to yt-dlp, avoid using options --write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, and --embed-thumbnail, and use --format - to manually select and validate download formats.
Moodle dl: yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) (CVE-2026-50023)
Description
A vulnerability in yt-dlp allows remote attackers to write arbitrary OS-shortcut files (.desktop, .url, .webloc) to the user's filesystem by bypassing the previous fix for CVE-2024-38519. This occurs because the allowlist for file extensions included unsafe shortcut file types to preserve functionality, which attackers can exploit via crafted media manifests. The malicious shortcut files can be disguised as subtitle or media files, potentially leading to social engineering attacks or arbitrary code execution. The issue is fixed in yt-dlp version 2026.06.09 by removing these extensions from the global allowlist except within the intended context. Users are advised to upgrade or apply strict usage restrictions if unable to update.
CVSS v3.1
Score 8.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The yt-dlp tool had a vulnerability (CVE-2026-50023) that allowed attackers to write arbitrary OS-shortcut files such as .desktop, .url, and .webloc by exploiting the inclusion of these extensions in the file extension allowlist intended for the --write-link option. Attackers can craft malicious m3u8 manifests with subtitle URIs pointing to files with these extensions, causing yt-dlp to write malicious shortcut files when options like --write-subs are used. These shortcut files can execute shell commands or point to remote executables, posing a risk of social engineering and code execution. The vulnerability bypasses the previous fix for CVE-2024-38519. The issue is resolved in yt-dlp version 2026.06.09 by restricting these extensions to the --write-link context only.
Potential Impact
Successful exploitation allows remote attackers to write malicious OS-shortcut files to the user's filesystem, which can be disguised as subtitle or media files. Because shortcut file extensions are often hidden, users may be tricked into executing malicious shortcuts, leading to phishing attacks or arbitrary code execution. The vulnerability has a high impact on confidentiality, integrity, and availability as indicated by a CVSS score of 8.3.
Mitigation Recommendations
A patch is available in yt-dlp version 2026.06.09 that removes .desktop, .url, and .webloc from the global file extension allowlist and restricts their use to the --write-link option context. Users should upgrade to this version immediately. If upgrading is not possible, users must only pass fully trusted URLs to yt-dlp, avoid using options --write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, and --embed-thumbnail, and use --format - to manually select and validate download formats.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-moodle-dl-CVE-2026-50023
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6aac8e6655bf5e2cf5491e7d
Added to database: 09/18/2026, 01:05:42 UTC
Last enriched: 09/18/2026, 01:56:57 UTC
Last updated: 09/18/2026, 02:06:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.