Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-94106: PHP-getID3 on Debian allows malicious filenames to run commands
CVE-2026-94106 · published 9 days ago
Summary
The PHP-getID3 library used on Debian systems can be tricked into running unwanted system commands if a file name contains special characters. This could let an attacker execute code with the same rights as the web application. Update the library to version 1.9.26 or later, or apply patches that properly escape file names.
What to do
- Update james-heinrich getid3 to version 1.9.26 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:16.04:LTS | canonical | php-getid3 | All versions |
| Debian:12 | debian | php-getid3 | All versions |
| – | james-heinrich | getid3 | < 1.9.26 |
Original advisory text
getID3 before 1.9.26 OS Command Injection via Unescaped Filenames
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
References
- https://github.com/JamesHeinrich/getID3 Third Party Advisory
- https://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49... Third Party Advisory
- https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754e... Third Party Advisory
- https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703... Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-94106 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94106... Vendor Advisory
- https://github.com/JamesHeinrich/getID3/issues/503 Third Party Advisory
- https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26 Third Party Advisory
- https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-94106 Vendor Advisory
- https://www.vulncheck.com/advisories/getid3-before-1.9.26-os-command-injection-v... Third Party Advisory
- https://ubuntu.com/security/CVE-2026-94106 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-94106 Third Party Advisory
Severity
9.4
Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published20 Sep 2026
Updated26 Sep 2026
First seen20 Sep 2026
Sources
CVE-2026-94106 · NVD
DEBIAN-CVE-2026-94106 · OSV
CVE-2026-94106 · OSV
GHSA-qf3m-pmjh-h6fx · GHSA
CVE-2026-94106 · MITRE
UBUNTU-CVE-2026-94106 · OSV
Track software like this
Free during beta