← Back to search

CVE-2026-94106

8.8 HIGHpublic exploit available

Published 2026-09-20 · Updated 2026-09-22

AI risk analysis

Summary
getID3 before 1.9.26 is vulnerable to OS command injection due to insufficient filename escaping, allowing attackers to inject arbitrary commands with process privileges.
Exploitability
Exploitation requires crafting a malicious filename with shell metacharacters, which is moderately difficult and depends on the application's handling of filenames.
Blast radius
If exploited, this vulnerability could lead to full system compromise, as arbitrary commands are executed with the process's privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to getID3 1.9.26 or later.
rceos-command-injectionfile-escaping

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.