CVE-2026-26331Disclosure(yt-dlp_project / yt-dlp)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch yt-dlp_project yt-dlp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a maliciously crafted URL. yt-dlp maintainers assume the impact of this vulnerability to be high for anyone who uses `--netrc-cmd` in their command/configuration or `netrc_cmd` in their Python scripts. Even though the maliciously crafted URL itself will look very suspicious to many users, it would be trivial for a maliciously crafted webpage with an inconspicuous URL to covertly exploit this vulnerability via HTTP redirect. Users without `--netrc-cmd` in their arguments or `netrc_cmd` in their scripts are unaffected. No evidence has been found of this exploit being used in the wild. yt-dlp version 2026.02.21 fixes this issue by validating all netrc "machine" values and raising an error upon unexpected input. As a workaround, users who are unable to upgrade should avoid using the `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter), or they should at least not pass a placeholder (`{}`) in their `--netrc-cmd` argument.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • yt-dlp

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-24); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Products
yt-dlp

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-22: 1Mentions · 2026-02-24: 4Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-05: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2202-2402-2803-0103-05
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-02-244
Disclosure3Patch1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
2026-03-051
Patch1
Full discourse8 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26331 Arbitrary Command Injection via --netrc-cmd in yt-dlp Severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26331

    Post summary

    A new CVE (CVE-2026-26331) has been disclosed, revealing an arbitrary command injection vulnerability in yt-dlp via the --netrc-cmd option.

    00011109
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26331 yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `… https://www.cve.org/CVERecord?id=CVE-2026-26331

    Post summary

    The text announces a vulnerability in yt‑dlp’s `--netrc-cmd` option affecting versions 2023.06.21 through 2026.02.21, but does not provide PoC, exploit, or patch details.

    00010151
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26331: yt-dlp: Downloading Shells Instead of Videos via --netrc-cmd A high-severity OS command injection vulnerability in yt-dlp allows attackers to execute arbitrary code via crafted URLs. By exploiting the `--netrc-cmd` feature and permissi... https://cvereports.com/reports/CVE-2026-26331

    Post summary

    The report announces a high‑severity OS command injection flaw in yt‑dlp that allows arbitrary code execution via crafted URLs using the --netrc-cmd feature.

    0001065
    31 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26331: HIGH] Critical security alert: Vulnerability in yt-dlp could allow arbitrary command injection through `--netrc-cmd` option. Update to version 2026.02.21 or avoid using `--netrc-cmd`. #cyber...#cve,CVE-2026-26331,#cybersecurity https://cvefind.com/CVE-2026-26331

    Post summary

    The post alerts about a high‑severity command injection vulnerability in yt‑dlp and recommends updating to version 2026.02.21 or disabling the vulnerable option.

    0001078
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26331** pertains to a command injection vulnerability in **yt-dlp**, a command-line tool used for downloading audio and video content from various websites. The vulnerability exists in versions prior to **2026.02.21** when the `--netrc-cmd` command-line option or the `netrc_cmd` Python API parameter is used. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-26331

    Post summary

    The post announces CVE‑2026‑26331, a command injection vulnerability in yt‑dlp affecting versions before 2026.02.21 when using the --netrc-cmd option or netrc_cmd API, but it does not provide a PoC, exploit, or patch information.

    0001067
    20 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Critical Security Alert for Fedora 42 Administrators 🚨 A high-severity vulnerability (CVE-2026-26331) has been patched in yt-dlp, the popular video downloader tool. Read more: 👉 https://tinyurl.com/58wksxpr #Security #Fedora https://t.co/C5HvlHpvBD

    Post summary

    The post announces that CVE-2026-26331, a high‑severity vulnerability in yt‑dlp, has been patched, but provides no further technical or exploitation details.

    00000130
    1.3K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26331 (CVSS:8.8, HIGH) is Analyzed. yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt..https://nvd.nist.gov/vuln/detail/CVE-2026-26331 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26331, noting its CVSS score and affected yt-dlp versions, but provides no PoC, exploit, or patch details.

    0000061
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26331 (CVSS:8.8, HIGH) is Analyzed. yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt..https://nvd.nist.gov/vuln/detail/CVE-2026-26331 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑26331 with CVSS 8.8, affecting yt‑dlp between specific release dates, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000047
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appyt-dlp_projectyt-dlp---

Explore more