Back

HIGH

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

Published Feb 24, 2026

Description

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a maliciously crafted URL. yt-dlp maintainers assume the impact of this vulnerability to be high for anyone who uses `--netrc-cmd` in their command/configuration or `netrc_cmd` in their Python scripts. Even though the maliciously crafted URL itself will look very suspicious to many users, it would be trivial for a maliciously crafted webpage with an inconspicuous URL to covertly exploit this vulnerability via HTTP redirect. Users without `--netrc-cmd` in their arguments or `netrc_cmd` in their scripts are unaffected. No evidence has been found of this exploit being used in the wild. yt-dlp version 2026.02.21 fixes this issue by validating all netrc "machine" values and raising an error upon unexpected input. As a workaround, users who are unable to upgrade should avoid using the `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter), or they should at least not pass a placeholder (`{}`) in their `--netrc-cmd` argument.

Affected products

Remediation

Red Hat statement

This is an IMPORTANT arbitrary command injection flaw in yt-dlp. The vulnerability occurs when the `--netrc-cmd` command-line option or `netrc_cmd` Python API parameter is actively used. Systems where this specific feature is not enabled or utilized are not affected by this issue.

Red Hat mitigation

To mitigate this issue, avoid using the `--netrc-cmd` command-line option or the `netrc_cmd` Python API parameter. If the `--netrc-cmd` option is essential for your workflow, ensure that a placeholder (`{}`) is not passed in the argument. Disabling this feature may impact workflows that rely on custom netrc command execution.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 24, 2026
Updated Feb 24, 2026
Reserved Feb 13, 2026
CISA Vulnrichment
Updated Feb 24, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 24, 2026
GHSA-G3GW-Q23R-PGQM