Impact
The vulnerability is an OS command injection in the ytdlp_download function of the Yt-dlp Download component. By modifying the URL argument, an attacker can inject arbitrary shell commands. The flaw is present in all releases up to version 4.1.0 and can be exploited remotely, with a high complexity rating. Exploits have been published, increasing the risk that an attacker may use them to gain unauthorized execution on the host.
Affected Systems
Affected are installations of the zackees transcribe‑anything package in versions 4.1.0 and earlier. The error occurs in the file src/transcribe_anything/ytldp_download.py within the Yt‑dlp Download component; no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. Remote exploitation is possible if the application processes untrusted URLs, and the high complexity and published exploits suggest that the risk to systems is non‑negligible, especially when the process runs with privileged permissions.
OpenCVE Enrichment