What’s New

yt-dlp 2026.06.09

2026.06.09

yt-dlp 2026.06.09

Added
  • Extract supplemental codecs from DASH manifests
  • Extract subtitles from abematv
  • Add lockfile and pinned extras
Changed
  • Raise minimum supported versions of Deno to v2.3.0, Node to v22, and deprecate Bun support limiting it to versions 1.2.11 through 1.3.14
  • Handle Pinia skipHydrate in _resolve_nuxt_array
  • Bump GitHub REST API version to 2026-03-10
  • Update random user agent version range to 143-149
Removed
  • Remove support for downloading HLS and DASH formats with aria2c downloader
Security
  • Restrict --exec option to only allow safe conversions in command templates, blocking vulnerable conversions like %()s
  • Fix file downloader cookie leak with curl by properly passing cookies so curl respects their scope
  • Restrict writing files with extensions .desktop, .url, or .webloc to only --write-link functionality context

Installation Discord Donate Documentation Nightly Master

A description of the various files is in the README

The zipimport Unix executable contains code licensed under ISC and MIT. The PyInstaller-bundled executables are subject to these and other licenses, all of which are compiled in THIRD_PARTY_LICENSES.txt


Important changes
  • The minimum supported versions of Deno, Node, and Bun have been raised. The minimum required version of Deno is now v2.3.0; supported Node versions are v22 and up; Bun support has been deprecated and limited to versions 1.2.11 through 1.3.14.
  • Security
    • Usage of vulnerable conversions (e.g. %()s) with the --exec option is an all-too-common pitfall. To remedy this, --exec now only allows safe conversions in its command templates.
      • Most users can simply replace %(...)s with %(...)q in their --exec argument(s). Numeric conversions are unaffected by this change. Using unsafe conversions with --exec poses a significant security risk. Read more
    • [CVE-2026-50019] File Downloader cookie leak with curl
      • Impact is limited to users of --downloader curl; cookies are now properly passed to curl so that it respects their scope
    • [CVE-2026-50023] Dangerous file type creation via insufficient filename sanitization
      • Writing files with the extensions .desktop, .url, or .webloc is now only allowed in the context of --write-link functionality
    • [CVE-2026-50574] Arbitrary code execution via manifest downloads with aria2c
      • Impact is limited to users of --downloader aria2c
      • Support for downloading HLS and DASH formats with aria2c has been removed. Users affected by this change should migrate to use -N for concurrent fragment downloads via the native downloader
Core changes
Extractor changes
Downloader changes
Postprocessor changes
Networking changes
Misc. changes
View original