Executive brief
getID3 is a PHP library that reads and extracts metadata from media files. The library fails to properly disable XML entity processing on PHP versions before 8.0, allowing attackers to craft malicious XML in media files to read local files, launch attacks on internal servers, or cause service outages through entity expansion attacks.
Technical details
An XML external entity (XXE) injection vulnerability exists in the XML2array helper function that does not properly disable entity loading on PHP before version 8.0. An attacker can supply a media file with malicious XML metadata to trigger local file disclosure, server-side request forgery (SSRF), or denial of service through billion laughs / entity expansion attacks.
Affected products
- James Heinrich getID3 through 1.9.26
Timeline
- 2026-09-20: disclosed