CVE-2026-94106
8.8 HIGHpublic exploit availablePublished 2026-09-20 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
- https://github.com/JamesHeinrich/getID3
- https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110
- https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
- https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
- https://github.com/JamesHeinrich/getID3/issues/503
- https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
- https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
All references
- https://github.com/JamesHeinrich/getID3
- https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110
- https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
- https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
- https://github.com/JamesHeinrich/getID3/issues/503
- https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
- https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
- https://www.vulncheck.com/advisories/getid3-before-1.9.26-os-command-injection-via-unescaped-filenames
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-13477
- HIGHCVE-2026-16022PoC
- HIGHCVE-2026-16793
- HIGHCVE-2026-18900PoC
- HIGHCVE-2026-55897PoC
- HIGHCVE-2026-62182PoC
- HIGHCVE-2026-62371PoC
- CRITICALCVE-2026-66902PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.