When yt-dlp's --netrc-cmd command-line option (or netrc_cmd Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a maliciously crafted URL.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2026-0054.json"