CVE-2026-26331: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-26331 is an OS command injection vulnerability in yt-dlp, a popular command-line audio/video downloader, affecting versions 2023.06.21 through versions prior to 2026.02.21. When the --netrc-cmd command-line option (or netrc_cmd Python API parameter) is used, an attacker can achieve arbitrary command injection on the user's system via a maliciously crafted URL. The vulnerability was published on February 21, 2026, and patched the same day in version 2026.02.21. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, yt-dlp Advisory).

Technical details

The root cause (CWE-78: Improper Neutralization of Special Elements used in an OS Command) lies in how yt-dlp handles the netrc "machine" value when constructing the shell command for --netrc-cmd. Three extractors — GetCourseRuIE, TeachableIE, and TeachableCourseIE — dynamically source the netrc machine value from the site's hostname and allow wildcard subdomain matches, which can result in a value containing special shell characters. The --netrc-cmd argument is executed via Python's subprocess.Popen with shell=True, meaning unvalidated special characters (e.g., ;, >, &) in the machine value are interpreted by the host shell. Critically, yt-dlp's generic extractor follows HTTP redirects, so any URL — even one with an innocuous appearance — can ultimately resolve to a maliciously crafted URL matching a vulnerable extractor. A proof-of-concept exploit is publicly available (yt-dlp Advisory, PoC Repo).

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands with the privileges of the user running yt-dlp, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, including data exfiltration, file modification, installation of malware, or denial of service. The attack is particularly dangerous because it can be triggered covertly via HTTP redirects from a legitimate-looking webpage, without the victim ever seeing a suspicious URL (Github Advisory, yt-dlp Advisory).

Exploitability

A public proof-of-concept exploit has been published on GitHub by the reporter (dxlerYT) shortly after disclosure (PoC Repo). Exploitation requires user interaction — specifically, the victim must be using --netrc-cmd and must process a URL (directly or via redirect) that triggers a vulnerable extractor. No privileges are required on the attacker's side. As of the time of reporting, no evidence of in-the-wild exploitation has been found, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.218% (44th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term (Github Advisory).

Exploitation steps

  1. Identify target users: Determine that the target is running yt-dlp with the --netrc-cmd option configured (e.g., in a script, cron job, or configuration file), as users without this option are unaffected.
  2. Craft a malicious URL: Construct a URL whose hostname contains shell metacharacters that will be interpreted as commands when substituted into the --netrc-cmd shell string. For example: https://;echo pwned>&2;#.getcourse.ru/video — the subdomain portion ;echo pwned>&2; becomes the netrc machine value.
  3. Set up an HTTP redirect (optional, stealthy): Host a webpage at an innocuous-looking URL that serves an HTTP 301/302 redirect to the malicious URL when it detects a yt-dlp User-Agent, making the attack covert.
  4. Deliver the URL to the victim: Trick the victim into running yt-dlp against the malicious URL or the redirect-serving page (e.g., via a shared link, embed, or automated pipeline).
  5. Command injection executes: When yt-dlp processes the URL through the GetCourseRuIE, TeachableIE, or TeachableCourseIE extractor, the netrc machine value (containing shell metacharacters) is substituted into the --netrc-cmd argument and executed via subprocess.Popen(shell=True), running the attacker's injected command with the victim's privileges (yt-dlp Advisory, Github Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the yt-dlp Python process (e.g., /bin/sh, /bin/bash, curl, wget, python, nc) with unusual arguments or connections.
  • Logs: yt-dlp output logs showing Executing command: entries where the command string contains shell metacharacters (;, >, &, |, $) or unexpected substrings beyond the expected netrc machine name.
  • Network: Outbound connections from the yt-dlp host to unexpected external IPs or domains immediately following a yt-dlp invocation; HTTP redirects from media URLs to hostnames containing shell special characters.
  • File System: New or modified files in the user's home directory, /tmp, or other writable locations created around the time of yt-dlp execution; new cron jobs, SSH authorized keys, or startup scripts added by the user account running yt-dlp.
  • Command History: Shell history entries showing yt-dlp invocations with --netrc-cmd and URLs containing characters such as ;, #, >, or & in the hostname portion (yt-dlp Advisory).

Mitigation and workarounds

The primary remediation is to upgrade yt-dlp to version 2026.02.21 or later, which fixes the issue by validating all netrc "machine" values against an allowlist of shell-safe characters ([a-zA-Z0-9._-]) and raising an error on unexpected input. The fix also tightens extractor URL regexes for GetCourseRuIE, TeachableIE, TeachableCourseIE, and PornHubIE to restrict hostname matching to safe character sets. For users unable to upgrade immediately: (1) stop using the --netrc-cmd command-line option or netrc_cmd Python API parameter entirely, or (2) at minimum, remove the {} placeholder from the --netrc-cmd argument to prevent hostname injection. Users who do not use --netrc-cmd are not affected and require no action (yt-dlp Advisory, yt-dlp Release).

Community reactions

The vulnerability received community attention on Reddit's r/youtubedl shortly after disclosure, with users discussing the impact and upgrade path (Reddit). Security news outlet The Hacker Wire published a dedicated write-up on the vulnerability (The Hacker Wire). Tenable released multiple Nessus detection plugins (IDs 299894, 299954, 301187) for the vulnerability, and Qualys also added detection. Linux distributions including Fedora and Mageia issued security advisories and updated their yt-dlp packages in response to the CVE.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

yt-dlp

Fixed

sid

yt-dlp: 2026.02.21-1

Fixed

trixie

yt-dlp

Affected

Ubuntu

Unknown

devel

yt-dlp

Unknown

jammy

yt-dlp

Unknown

jammy (esm-apps)

yt-dlp

Unknown

noble

yt-dlp

Unknown

noble (esm-apps)

yt-dlp

Unknown

resolute

yt-dlp

Unknown

resolute (esm-apps)

yt-dlp

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management