Critical severity9.8NVD Advisory· Published Jul 28, 2023· Updated Jun 17, 2026
CVE-2023-39018
CVE-2023-39018
Description
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.bramp.ffmpeg:ffmpegMaven | <= 0.7.0 | — |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/bramp/ffmpeg-cli-wrapper/issues/291nvdExploitIssue TrackingPatchWEB
- github.com/advisories/GHSA-2jx3-fx5f-r2c6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-39018ghsaADVISORY
- github.com/bramp/ffmpeg-cli-wrapper/blob/master/src/main/java/net/bramp/ffmpeg/FFmpeg.javanvdWEB
News mentions
0No linked articles in our index yet.