Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11986 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2. |
Github GHSA |
GHSA-2jh5-g5ch-43q5 | YoutubeDLSharp allows command injection on windows system due to non sanitized arguments |
Thu, 24 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2. | |
| Title | YoutubeDLSharp allows command injection on windows system due to non sanitized arguments | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-24T19:04:13.866Z
Reserved: 2025-04-17T20:07:08.555Z
Link: CVE-2025-43858
Updated: 2025-04-24T19:04:10.771Z
Status : Deferred
Published: 2025-04-24T18:15:20.120
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-43858
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA