SCA: security update for yt-dlp (GHSA-v8mc-9377-rwjj)

high Tenable Self-Hosted Container Security Plugin ID 419199

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the
external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak
them when the host for download fragments differs from their parent manifest's host. This vulnerable
behavior is present in yt-dlp prior to 2023.07.06 and nightly 2023.07.06.185519. All native and external
downloaders are affected, except for `curl` and `httpie` (version 3.1.0 or later). At the file download
stage, all cookies are passed by yt-dlp to the file downloader as a `Cookie` header, thereby losing their
scope. This also occurs in yt-dlp's info JSON output, which may be used by external tools. As a result,
the downloader or external tool may indiscriminately send cookies with requests to domains or paths for
which the cookies are not scoped. yt-dlp version 2023.07.06 and nightly 2023.07.06.185519 fix this issue
by removing the `Cookie` header upon HTTP redirects; having native downloaders calculate the `Cookie`
header from the cookiejar, utilizing external downloaders' built-in support for cookies instead of passing
them as header arguments, disabling HTTP redirectiong if the external downloader does not have proper
cookie support, processing cookies passed as HTTP headers to limit their scope, and having a separate
field for cookies in the info dict storing more information about scoping Some workarounds are available
for those who are unable to upgrade. Avoid using cookies and user authentication methods. While extractors
may set custom cookies, these usually do not contain sensitive information. Alternatively, avoid using
`--load-info-json`. Or, if authentication is a must: verify the integrity of download links from unknown
sources in browser (including redirects) before passing them to yt-dlp; use `curl` as external downloader,
since it is not impacted; and/or avoid fragmented formats such as HLS/m3u8, DASH/mpd and ISM.
(CVE-2023-35934)

See Also

https://github.com/advisories/GHSA-v8mc-9377-rwjj

Plugin Details

Severity: High

ID: 419199

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.58

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2023-35934

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/6/2023

Vulnerability Publication Date: 7/6/2023

Reference Information

CVE: CVE-2023-35934