VYPR

Getid3

by JamesHeinrich

Source repositories

CVEs (2)

  • CVE-2026-94106HigSep 20, 2026
    risk 0.50cvss 8.8epss 0.02

    getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the…

  • CVE-2026-94108MedSep 20, 2026
    risk 0.35cvss 6.5epss 0.01

    getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side…