Description
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
Published: 2026-09-20
Score: 8.7 High
EPSS: 1.7% Low
KEV: No
Impact: OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in a shell‑out handler within the getID3 library, where filenames are interpolated directly into command strings without proper escaping. This flaw is a classic OS command injection flaw, classified as CWE‑78. If an attacker supplies a filename that includes shell metacharacters, the commands are executed with the privileges of the process that embeds getID3, potentially allowing arbitrary code execution.

Affected Systems

The affected product is the PHP library getID3 by James Heinrich, any installation before version 1.9.26. Versions 1.9.26 and later include the fix and do not contain the injection issue.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity risk. The EPSS score is 2%, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack is likely exploitable in a typical remote context when an application that uses getID3 can receive or control filenames—such as a media management web service—if the code path is reachable via user‑supplied input. Exfiltration or persistence can be achieved through arbitrary command execution.

Generated by OpenCVE AI on September 21, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the getID3 library to version 1.9.26 or later, which removes the unescaped filename handling.
  • If an upgrade is not possible, ensure that any filenames passed to getID3 are first sanitized or validated to strip shell metacharacters before being processed.
  • Consider configuring the application to run getID3 in a restricted environment with limited privileges to reduce the impact of any potential successful injection.

Generated by OpenCVE AI on September 21, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
Title getID3 before 1.9.26 OS Command Injection via Unescaped Filenames
First Time appeared Getid3
Getid3 getid3
Weaknesses CWE-78
CPEs cpe:2.3:a:getid3:getid3:*:*:*:*:*:*:*:*
Vendors & Products Getid3
Getid3 getid3
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:46:46.047Z

Reserved: 2026-09-20T10:56:43.390Z

Link: CVE-2026-94106

cve-icon Vulnrichment

Updated: 2026-09-21T16:42:46.281Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-20T12:17:06.110

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-94106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T15:30:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')