YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2. | |
Title | YoutubeDLSharp allows command injection on windows system due to non sanitized arguments | |
Weaknesses | CWE-77 CWE-78 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-24T18:04:48.447Z
Updated: 2025-04-24T19:04:13.866Z
Reserved: 2025-04-17T20:07:08.555Z
Link: CVE-2025-43858

Updated: 2025-04-24T19:04:10.771Z

Status : Awaiting Analysis
Published: 2025-04-24T18:15:20.120
Modified: 2025-04-29T13:52:28.490
Link: CVE-2025-43858

No data.