getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
https://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
https://github.com/JamesHeinrich/getID3/issues/503
https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
Published: 2026-09-20
Updated: 2026-09-20
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.7
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High