OS Command Injection in getID3 - #VU150784

 

OS Command Injection in getID3 - #VU150784

Published: September 17, 2026


Vulnerability identifier: #VU150784
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary system commands.

The vulnerability exists due to improper neutralization of special elements used in an os command in multiple helperapp shell-out handlers when processing media files with crafted filenames. A remote user can supply a media file with a crafted filename to execute arbitrary system commands.

Injected commands run with the privileges of the web server or PHP process user.


Affected software

getID3

Remediation

Install security update from vendor's website.

getID3 - update to 1.9.26

External References

Related Security Bulletins