Episode Details
Back to Episodes
From Global Allowlist to RCE: Breaking Down CVE-2026-50023 in yt-dlp
Description
This story was originally published on HackerNoon at: https://hackernoon.com/from-global-allowlist-to-rce-breaking-down-cve-2026-50023-in-yt-dlp.
How a shortcut-extension exception in yt-dlp's CVE-2024-38519 fix opened the door to CVE-2026-50023, and what the follow-up bug teaches us.
Check more stories related to tech-stories at: https://hackernoon.com/c/tech-stories.
You can also check exclusive content about #vulnerability-research, #cve-2026-50023, #yt-dlp, #remote-code-execution, #filename-sanitization, #hls-subtitles, #security-patch-bypass, #allowist-security, and more.
This story was written by: @pavanchow. Learn more about this writer by checking @pavanchow's about page,
and for more stories, please visit hackernoon.com.
A fix for filename sanitization kept dangerous extensions on a global allowlist. I bypassed it by crafting an HLS manifest that forced yt-dlp to write a malicious .desktop file during a standard subtitle download. The patch moved the exception to the feature boundary, but a follow-up CVE proved the class was not fully closed.