Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia 9 yt-dlp Important Command Injection Risk MGASA-2026-0054

mageia
Calendar Grey March 10, 2026
Dist Mageia Esm H88
Updated yt-dlp packages address a critical command injection vulnerability affecting Mageia releases. Learn more here.
MGASA-2026-0054 - Updated yt-dlp packages fix security vulnerability

Summary

Description: When yt-dlp's --netrc-cmd command-line option (or netrc_cmd Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a maliciously crafted URL.

References

- https://bugs.mageia.org/show_bug.cgi?id=35183

- https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm

- https://github.com/yt-dlp/yt-dlp/compare/2026.02.04...2026.03.03

- https://www.cve.org/CVERecord?id=CVE-2026-26331

Resolution

SRPMS

- 9/core/yt-dlp-2026.03.03-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 10 Mar 2026
URL: https://advisories.mageia.org/MGASA-2026-0054.html
Type: security
CVE: CVE-2026-26331

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here