---
title: "CVE-2023-40581\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-40581?format=md
keywords: index, follow
---

# CVE-2023-40581

Publication date 25 September 2023

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2023-40581?format=md#impact-score)

Toggle side navigation

## Description

yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp
allows the user to provide shell command lines to be executed at various
stages in its download steps through the `--exec` flag. This flag allows
output template expansion in its argument, so that metadata values may be
used in the shell commands. The metadata fields can be combined with the
`%q` conversion, which is intended to quote/escape these values so they can
be safely passed to the shell. However, the escaping used for `cmd` (the
shell used by Python's `subprocess` on Windows) does not properly escape
special characters, which can allow for remote code execution if `--exec`
is used directly with maliciously crafted remote data. This vulnerability
only impacts `yt-dlp` on Windows, and the vulnerability is present
regardless of whether `yt-dlp` is run from `cmd` or from `PowerShell`.
Support for output template expansion in `--exec`, along with this
vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp
version 2023.09.24 fixes this issue by properly escaping each special
character. `\n` will be replaced by `\r` as no way of escaping it has been
found. It is recommended to upgrade yt-dlp to version 2023.09.24 as soon as
possible. Also, always be careful when using --exec, because while this
specific vulnerability has been patched, using unvalidated input in shell
commands is inherently dangerous. For Windows users who are not able to
upgrade: 1. Avoid using any output template expansion in --exec other than
{} (filepath). 2. If expansion in --exec is needed, verify the fields you
are using do not contain ", | or &. 3. Instead of using --exec, write the
info json and load the fields from it instead.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2023-40581?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| yt-dlp | 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

issue affects Windows only

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40581)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-40581)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-40581)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-40581)

### Other references

* <https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-42h4-v29r-42qg>
* <https://github.com/yt-dlp/yt-dlp/releases/tag/2021.04.11>
* <https://github.com/yt-dlp/yt-dlp/releases/tag/2023.09.24>
* <https://github.com/yt-dlp/yt-dlp/commit/de015e930747165dbb8fcd360f8775fd973b7d6e>
* <https://github.com/yt-dlp/yt-dlp-nightly-builds/releases/tag/2023.09.24.003044>
* <https://www.cve.org/CVERecord?id=CVE-2023-40581>
