CVE-2026-94106

Source
https://cve.org/CVERecord?id=CVE-2026-94106
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94106.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94106
Aliases
  • GHSA-qf3m-pmjh-h6fx
Downstream
Published
2026-09-20T11:09:40Z
Modified
2026-09-21T03:46:00Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
getID3 before 1.9.26 OS Command Injection via Unescaped Filenames
Details

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94106.json"
}
References

Affected packages

Git / github.com/jamesheinrich/getid3

Affected ranges

Type
GIT
Repo
https://github.com/jamesheinrich/getid3
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.9.26"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.9.7
v1.*
v1.9.10
v1.9.11
v1.9.12
v1.9.13
v1.9.14
v1.9.15
v1.9.16
v1.9.17
v1.9.18
v1.9.19
v1.9.20
v1.9.21
v1.9.22
v1.9.23
v1.9.24
v1.9.25
v1.9.8
v1.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94106.json"