CVE-2025-43858
CVSS 3.1 Score 9.2 of 10 (high)
Details
Summary
CVE-2025-43858 is a vulnerability affecting the YoutubeDLSharp library, a wrapper for command-line video downloaders youtube-dl and yt-dlp. In versions prior to 1.1.2 and starting from 1.0.0-beta4, an unsafe argument conversion allows the injection of malicious commands when starting `yt-dlp` from a Windows command prompt, with the default setting `UseWindowsEncodingWorkaround` being vulnerable. This issue can lead to security risks as users cannot disable this default value when using built-in methods from the YoutubeDL.cs file. This vulnerability has been addressed in version 1.1.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- YoutubeDLSharp