CVE-2026-50023 | yt-dlp up to 2026.06.8 improper restriction of names for files and other resources (GHSA-c6mh-fpjc-4pr3 / Nessus ID 322360)
A vulnerability marked as problematic has been reported in yt-dlp up to 2026.06.8. This affects an unknown part. Performing a manipulation results in improper restriction of names for files and other resources.
This vulnerability is reported as CVE-2026-50023. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.