Skip to main content

Moodle dl: yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519) (CVE-2026-50023)

0
High
Published: 08/13/2026 (08/13/2026, 17:14:32 UTC)
Source: GCVE Database
Product: moodle-dl

Description

A vulnerability in yt-dlp allows remote attackers to write arbitrary OS-shortcut files (.desktop, .url, .webloc) to the user's filesystem by bypassing the previous fix for CVE-2024-38519. This occurs because the allowlist for file extensions included unsafe shortcut file types to preserve functionality, which attackers can exploit via crafted media manifests. The malicious shortcut files can be disguised as subtitle or media files, potentially leading to social engineering attacks or arbitrary code execution. The issue is fixed in yt-dlp version 2026.06.09 by removing these extensions from the global allowlist except within the intended context. Users are advised to upgrade or apply strict usage restrictions if unable to update.

CVSS v3.1

Score 8.3high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected software

Homebrewmore threats →ghsa
moodle-dl
pkg:brew/moodle-dl
Affected versions
>=2.3.13 <2.3.13_11

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 01:56:57 UTC

Technical Analysis

The yt-dlp tool had a vulnerability (CVE-2026-50023) that allowed attackers to write arbitrary OS-shortcut files such as .desktop, .url, and .webloc by exploiting the inclusion of these extensions in the file extension allowlist intended for the --write-link option. Attackers can craft malicious m3u8 manifests with subtitle URIs pointing to files with these extensions, causing yt-dlp to write malicious shortcut files when options like --write-subs are used. These shortcut files can execute shell commands or point to remote executables, posing a risk of social engineering and code execution. The vulnerability bypasses the previous fix for CVE-2024-38519. The issue is resolved in yt-dlp version 2026.06.09 by restricting these extensions to the --write-link context only.

Potential Impact

Successful exploitation allows remote attackers to write malicious OS-shortcut files to the user's filesystem, which can be disguised as subtitle or media files. Because shortcut file extensions are often hidden, users may be tricked into executing malicious shortcuts, leading to phishing attacks or arbitrary code execution. The vulnerability has a high impact on confidentiality, integrity, and availability as indicated by a CVSS score of 8.3.

Mitigation Recommendations

A patch is available in yt-dlp version 2026.06.09 that removes .desktop, .url, and .webloc from the global file extension allowlist and restricts their use to the --write-link option context. Users should upgrade to this version immediately. If upgrading is not possible, users must only pass fully trusted URLs to yt-dlp, avoid using options --write-subs, --write-auto-subs, --embed-subs, --write-thumbnail, --write-all-thumbnails, and --embed-thumbnail, and use --format - to manually select and validate download formats.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-moodle-dl-CVE-2026-50023
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6aac8e6655bf5e2cf5491e7d

Added to database: 09/18/2026, 01:05:42 UTC

Last enriched: 09/18/2026, 01:56:57 UTC

Last updated: 09/18/2026, 02:06:40 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses