Source: php-getid3 Version: 1.9.25+dfsg-1 Severity: important Tags: security upstream Forwarded: https://github.com/JamesHeinrich/getID3/issues/503 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for php-getid3. CVE-2026-94106[0]: | getID3 before 1.9.26 contains an OS command injection vulnerability | in shell-out handlers that fail to escape filenames in command | strings. Attackers can craft malicious filenames containing shell | metacharacters to inject arbitrary commands executed with the | privileges of the process embedding getID3. While it was initially on the Windows only code path, the second follow up contains as well fixes on the *nix codepath, so filling this bug. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-94106 https://www.cve.org/CVERecord?id=CVE-2026-94106 [1] https://github.com/JamesHeinrich/getID3/issues/503 [2] https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx [3] https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6 [4] https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

