Executive brief
getID3 is a PHP library that extracts metadata from audio and video files. Versions before 1.9.26 contain a command injection flaw in shell-out handlers that fail to properly escape filenames passed to system commands. An attacker can craft malicious filenames containing shell metacharacters to execute arbitrary code with the privileges of the web server or application embedding getID3, potentially leading to full system compromise.
Technical details
The vulnerability exists in shell-out handlers within getID3 that construct OS command strings using unescaped filenames. An attacker can inject shell metacharacters through a crafted filename to break out of the intended command and execute arbitrary shell commands. This requires an attacker to control the filename input processed by getID3, and the vulnerability is exploitable on systems where shell command execution is enabled within the library.
Affected products
- James Heinrich getID3 before 1.9.26
Timeline
- 2026-09-20: disclosed