PT-2025-41824 · Unknown+1 · Yt-Grabber-Tui+1

Zheny-Creator

·

Published

2025-10-13

·

Updated

2025-10-14

·

CVE-2025-62363

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yt-grabber-tui versions prior to 1.0-rc
Description yt-grabber-tui is a terminal user interface application for downloading videos. Versions before 1.0-rc allow configuration of the path to the yt-dlp executable via the path to yt dlp configuration setting. An attacker with write access to the configuration file or the filesystem location of the configured executable can replace the executable with malicious code or create a symbolic link to an arbitrary executable. When the application invokes yt-dlp, the malicious code is executed with the privileges of the user running yt-grabber-tui.
Recommendations Update to version 1.0-rc or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62363
GHSA-94C4-WH57-8P9C

Affected Products

Yt-Dlp
Yt-Grabber-Tui