getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.
https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-3hf9-j62w-m548
https://github.com/JamesHeinrich/getID3/pull/506
https://github.com/JamesHeinrich/getID3/issues/505
https://github.com/JamesHeinrich/getID3/commit/ce50b4b23439f87716653099718fa1c11b3d15c4
Published: 2026-09-20
Updated: 2026-09-20
Base Score: 6.1
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:P
Severity: Medium
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Severity: Medium
Base Score: 8.3
Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Severity: High