CVE-2026-94108

high

Description

getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.

References

https://www.vulncheck.com/advisories/getid3-through-1.9.26-xml-external-entity-injection-via-xml2array

https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-3hf9-j62w-m548

https://github.com/JamesHeinrich/getID3/pull/506

https://github.com/JamesHeinrich/getID3/issues/505

https://github.com/JamesHeinrich/getID3/commit/ce50b4b23439f87716653099718fa1c11b3d15c4

https://github.com/JamesHeinrich/getID3/blob/0bc49beff9c274f2490ce9a4bb76f5ef50881e08/getid3/getid3.lib.php#L742-L755

https://github.com/JamesHeinrich/getID3

Details

Source: Mitre, NVD

Published: 2026-09-20

Updated: 2026-09-20

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 8.3

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: High