CVETodo[verified]@CveTodoDisclosure
The post announces CVE‑2026‑26331, a command injection vulnerability in yt‑dlp affecting versions before 2026.02.21 when using the --netrc-cmd option or netrc_cmd API, but it does not provide a PoC, exploit, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new CVE (CVE-2026-26331) has been disclosed, revealing an arbitrary command injection vulnerability in yt-dlp via the --netrc-cmd option.
CVE@CVEnewDisclosure
The text announces a vulnerability in yt‑dlp’s `--netrc-cmd` option affecting versions 2023.06.21 through 2026.02.21, but does not provide PoC, exploit, or patch details.
cvereports@_cvereportsDisclosure
The report announces a high‑severity OS command injection flaw in yt‑dlp that allows arbitrary code execution via crafted URLs using the --netrc-cmd feature.
CVEFind.com@CveFindComPatch
The post alerts about a high‑severity command injection vulnerability in yt‑dlp and recommends updating to version 2026.02.21 or disabling the vulnerable option.
Ferramentas Linux@Cezar_H_LinuxPatch
The post announces that CVE-2026-26331, a high‑severity vulnerability in yt‑dlp, has been patched, but provides no further technical or exploitation details.
CRAC Learning - Tech@cracbotDisclosure
The post references CVE-2026-26331, noting its CVSS score and affected yt-dlp versions, but provides no PoC, exploit, or patch details.
CRAC Learning - Tech@cracbotDisclosure
The tweet announces CVE‑2026‑26331 with CVSS 8.8, affecting yt‑dlp between specific release dates, but offers no PoC, exploit, patch, or evidence of active exploitation.