Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-94106: PHP-getID3 on Debian allows malicious filenames to run commands

CVE-2026-94106 · published 9 days ago
Summary

The PHP-getID3 library used on Debian systems can be tricked into running unwanted system commands if a file name contains special characters. This could let an attacker execute code with the same rights as the web application. Update the library to version 1.9.26 or later, or apply patches that properly escape file names.

What to do
  • Update james-heinrich getid3 to version 1.9.26 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:16.04:LTS canonical php-getid3 All versions
Debian:12 debian php-getid3 All versions
– james-heinrich getid3 < 1.9.26
Original advisory text
getID3 before 1.9.26 OS Command Injection via Unescaped Filenames
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
Severity
9.4 Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published20 Sep 2026
Updated26 Sep 2026
First seen20 Sep 2026
Track software like this
Free during beta