OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94106

HIGH · CVSS 8.8 EPSS 1.66% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability exists in getID3 versions prior to 1.9.26, where improper handling of filenames in shell-out commands allows for OS command injection. This flaw enables attackers to execute arbitrary commands with the privileges of the process running getID3, potentially leading to system compromise. Organizations utilizing getID3 for media processing should prioritize patching this vulnerability to mitigate the associated risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94106
Severity
HIGH
CVSS
8.8
EPSS
1.66%

Original NVD Description

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.