CVE-2026-94106

Summary

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

Affected Software

VendorProductVersion RangeStatus
james-heinrichgetid30 < 1.9.26affected
james-heinrichgetid31.9.26unaffected

Weaknesses

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References