CVE-2026-94106
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings.
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 20, 2026 · Last modified: Sep 20, 2026 · CWE-78
Not enough EPSS history yet.
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
- github.comhttps://github.com/JamesHeinrich/getID3
- github.comhttps://github.com/JamesHeinrich/getID3/blob/fefffe762b02be155dcc32eec57feff8a49bc4b5/getid3/write.vorbiscomment.php#L85-L110
- github.comhttps://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4
- github.comhttps://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
- github.comhttps://github.com/JamesHeinrich/getID3/issues/503
- github.comhttps://github.com/JamesHeinrich/getID3/releases/tag/v1.9.26
- github.comhttps://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
- www.vulncheck.comhttps://www.vulncheck.com/advisories/getid3-before-1.9.26-os-command-injection-via-unescaped-filenames
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-939589.1 CRI81.5%
——24A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.1dCVE-2026-840858.1 HIG24.9%
——7IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.2dCVE-2026-840717.2 HIG72.2%
——22IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.2dCVE-2026-828928.1 HIG32.4%
——10IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.2dCVE-2026-828878.8 HIG34.9%
——10IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.2dCVE-2026-819377.2 HIG72.2%
——22IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.2d