HIGH 8.7 NVD

CVE-2026-94106

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

References

Published: 2026-09-20 · Source: NVD · Feed updated: 2026-09-20
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-20 via NVD.
vulnfeed aggregates 14832 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.