
🚨 getID3 CVE-2026-94106 — CVSS 8.8 A crafted filename is enough. shell_exec() called WITHOUT escapeshellarg(). Affected: through 1.9.25 Fixed: 1.9.26 UPGRADE NOW. → https://threataft.com/articles/getid3-cve-2026-94106-os-command-injection-malicious-filenames #getID3 #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

