yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
Published Feb 24, 2026
8.8
HIGHCVSS 3.1
EPSS 2.01%
Description
yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a maliciously crafted URL. yt-dlp maintainers assume the impact of this vulnerability to be high for anyone who uses `--netrc-cmd` in their command/configuration or `netrc_cmd` in their Python scripts. Even though the maliciously crafted URL itself will look very suspicious to many users, it would be trivial for a maliciously crafted webpage with an inconspicuous URL to covertly exploit this vulnerability via HTTP redirect. Users without `--netrc-cmd` in their arguments or `netrc_cmd` in their scripts are unaffected. No evidence has been found of this exploit being used in the wild. yt-dlp version 2026.02.21 fixes this issue by validating all netrc "machine" values and raising an error upon unexpected input. As a workaround, users who are unable to upgrade should avoid using the `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter), or they should at least not pass a placeholder (`{}`) in their `--netrc-cmd` argument.
Affected products
-
- Version >= 2023.06.21, < 2026.02.21StatusaffectedConstraints-
- Version
- ≥ 2023.06.21 · < 2026.02.21
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This is an IMPORTANT arbitrary command injection flaw in yt-dlp. The vulnerability occurs when the `--netrc-cmd` command-line option or `netrc_cmd` Python API parameter is actively used. Systems where this specific feature is not enabled or utilized are not affected by this issue.
Red Hat mitigation
To mitigate this issue, avoid using the `--netrc-cmd` command-line option or the `netrc_cmd` Python API parameter. If the `--netrc-cmd` option is essential for your workflow, ensure that a placeholder (`{}`) is not passed in the argument. Disabling this feature may impact workflows that rely on custom netrc command execution.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.01% (0.02011) | 80.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.60% (0.01596) | 72.48th | v5 (v2026.06.15) |
| Feb 24, 2026 | 0.12% (0.00119) | 30.85th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-26331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2442143 Issue Tracking
- https://github.com/advisories/GHSA-g3gw-q23r-pgqm Advisory
- https://github.com/yt-dlp/yt-dlp/commit/1fbbe29b99dc61375bf6d786f824d9fcf6ea9c1a x_refsource_MISCPatch
- https://github.com/yt-dlp/yt-dlp/releases/tag/2026.02.21 x_refsource_MISCProductRelease Notes
- https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26331
- https://www.cve.org/CVERecord?id=CVE-2026-26331
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-26331 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2442143 | Issue Tracking | |
| https://github.com/advisories/GHSA-g3gw-q23r-pgqm | Advisory | |
| https://github.com/yt-dlp/yt-dlp/commit/1fbbe29b99dc61375bf6d786f824d9fcf6ea9c1a | x_refsource_MISCPatch | |
| https://github.com/yt-dlp/yt-dlp/releases/tag/2026.02.21 | x_refsource_MISCProductRelease Notes | |
| https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm | x_refsource_CONFIRMExploitMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-26331 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-26331 |
Change history (0)
No recorded changes yet.