Impact
The vulnerability resides in a shell‑out handler within the getID3 library, where filenames are interpolated directly into command strings without proper escaping. This flaw is a classic OS command injection flaw, classified as CWE‑78. If an attacker supplies a filename that includes shell metacharacters, the commands are executed with the privileges of the process that embeds getID3, potentially allowing arbitrary code execution.
Affected Systems
The affected product is the PHP library getID3 by James Heinrich, any installation before version 1.9.26. Versions 1.9.26 and later include the fix and do not contain the injection issue.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk. The EPSS score is 2%, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack is likely exploitable in a typical remote context when an application that uses getID3 can receive or control filenames—such as a media management web service—if the code path is reachable via user‑supplied input. Exfiltration or persistence can be achieved through arbitrary command execution.
OpenCVE Enrichment