Junglewise Threat Intelligence

CVE-2026-26331: PYSEC-2026-3432 - yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

CVE-2026-26331 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: yt-dlp (PyPI). Vendors: PyPI.

Executive brief

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

Affected products

  • PyPI yt-dlp

Related threats