🛡️ MGASA-2026-0234 — yt-dlp
Description
Updated yt-dlp packages fix security vulnerabilities
CVE-2026-50019 If curl is used as an external downloader for yt-dlp,
cookies may be leaked to an unintended host upon HTTP redirect or when
the host for download fragments differs from their parent manifest's.
CVE-2026-50023 A vulnerability exists in yt-dlp that allows a remote
attacker to write arbitrary OS-shortcut files (such as .desktop, .url,
.webloc) to the user's filesystem, bypassing the remediation for
CVE-2024-38519.
CVE-2026-50574 If aria2c is used as an external downloader for a
fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes
insufficiently sanitized input to aria2c that allows an attacker to
perform an arbitrary file write. On Windows platforms, this can lead to
immediate arbitrary code execution. On non-Windows platforms, this can
lead to arbitrary code execution upon the next invocation of yt-dlp.
For mageia 9 we import yt-dlp-ejs to ensure the application still works.
Affected software
MGASA-2026-0234 is recorded against 2 packages.
- yt-dlp (fixed in 2026.06.09-1.1.mga9)
- yt-dlp-ejs (fixed in 0.8.0-1.mga9)
Timeline and source
Published on 4 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
github.com (Advisory)
github.com (Advisory)
github.com (Advisory)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| yt-dlp | — | 2026.06.09-1.1.mga9 |
| yt-dlp-ejs | — | 0.8.0-1.mga9 |
References
Similar Threats
- High CVE-2026-55404
- Unknown DEBIAN-CVE-2026-55404
- Unknown DEBIAN-CVE-2026-50574
- Unknown DEBIAN-CVE-2026-50019
- Unknown DEBIAN-CVE-2026-50023
More MGASA 2026 advisories
Browse all of MGASA 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MGASA-2026-0234?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2026-0234 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.