CVE-2026-50574 | yt-dlp up to 2026.06.8 injection (GHSA-vx4q-3cr2-7cg2 / Nessus ID 322360)
A vulnerability has been found in yt-dlp up to 2026.06.8 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2026-50574. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.