{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0054",
  "published": "2026-03-10T16:47:59Z",
  "modified": "2026-03-10T16:07:42Z",
  "summary": "Updated yt-dlp packages fix security vulnerability",
  "details": "When yt-dlp's --netrc-cmd command-line option (or netrc_cmd Python API\nparameter) is used, an attacker could achieve arbitrary command\ninjection on the user's system with a maliciously crafted URL.\n",
  "upstream": [
    "CVE-2026-26331"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0054.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=35183"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-g3gw-q23r-pgqm"
    },
    {
      "type": "WEB",
      "url": "https://github.com/yt-dlp/yt-dlp/compare/2026.02.04...2026.03.03"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "yt-dlp",
        "purl": "pkg:rpm/mageia/yt-dlp?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2026.03.03-1.1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
