fix(downloader): sanitize yt-dlp output template filename

The user-chosen remote-download filename becomes a yt-dlp -o template
verbatim - "../" could escape the task temp dir and "%(field)s" could
expand yt-dlp metadata. Names with path separators, template fields,
or ".." now fall back to the default %(title)s.%(ext)s template.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
pull/3582/head
Tomas Dvorak 2 weeks ago
parent e1575e3d97
commit 456a513034

@ -301,7 +301,11 @@ func (m *RemoteDownloadTask) buildDownloadOptions(ctx context.Context, base map[
} }
case types.DownloaderProviderYtDlp: case types.DownloaderProviderYtDlp:
if isHttpSrc { if isHttpSrc {
if m.state.FileName != "" { // "output" becomes a yt-dlp -o template: reject path separators
// and "%(" template fields so a user-chosen name cannot escape
// the task temp dir or expand yt-dlp metadata.
if m.state.FileName != "" && !strings.ContainsAny(m.state.FileName, `/\`) &&
!strings.Contains(m.state.FileName, "%(") && m.state.FileName != ".." {
options["output"] = m.state.FileName options["output"] = m.state.FileName
} }
if m.state.HTTPUsername != "" { if m.state.HTTPUsername != "" {

Loading…
Cancel
Save