{"id":"CVE-2026-94106","published":"2026-09-20T12:17:06.110","lastModified":"2026-09-22T20:25:55.870","description":"getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/JamesHeinrich/getID3","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/issues/503","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx","tags":[]},{"url":"https://www.vulncheck.com/advisories/getid3-before-1.9.26-os-command-injection-via-unescaped-filenames","tags":[]}],"exploitRefs":[{"url":"https://github.com/JamesHeinrich/getID3","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/issues/503","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26","tags":[]},{"url":"https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx","tags":[]}],"hasPoc":true,"ai":{"summary":"getID3 before 1.9.26 is vulnerable to OS command injection due to insufficient filename escaping, allowing attackers to inject arbitrary commands with process privileges.","exploitability":"Exploitation requires crafting a malicious filename with shell metacharacters, which is moderately difficult and depends on the application's handling of filenames.","blast_radius":"If exploited, this vulnerability could lead to full system compromise, as arbitrary commands are executed with the process's privileges.","remediation":"Upgrade to getID3 1.9.26 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","os-command-injection","file-escaping"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:19:22.096Z"}}