CVE-2026-94106
8.8 HIGHpublic exploit availablePublished 2026-09-20 · Updated 2026-09-22
AI risk analysis
- Summary
- getID3 before 1.9.26 is vulnerable to OS command injection due to insufficient filename escaping, allowing attackers to inject arbitrary commands with process privileges.
- Exploitability
- Exploitation requires crafting a malicious filename with shell metacharacters, which is moderately difficult and depends on the application's handling of filenames.
- Blast radius
- If exploited, this vulnerability could lead to full system compromise, as arbitrary commands are executed with the process's privileges.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to getID3 1.9.26 or later.
rceos-command-injectionfile-escaping
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
- https://github.com/JamesHeinrich/getID3
- https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110
- https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
- https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
- https://github.com/JamesHeinrich/getID3/issues/503
- https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
- https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
All references
- https://github.com/JamesHeinrich/getID3
- https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110
- https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
- https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
- https://github.com/JamesHeinrich/getID3/issues/503
- https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
- https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
- https://www.vulncheck.com/advisories/getid3-before-1.9.26-os-command-injection-via-unescaped-filenames
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-100896PoC
- CRITICALCVE-2026-101001PoC
- CRITICALCVE-2026-101002PoC
- CRITICALCVE-2026-101072PoC
- CRITICALCVE-2026-101075PoC
- CRITICALCVE-2026-101076PoC
- CRITICALCVE-2026-102911PoC
- HIGHCVE-2026-15027
Related by shared AI tags and CWE weakness class. Browse the full archive.