CVE-2026-94106

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-21: 209-21
Referenced assets2 URLs
Full discourse2 posts
  • ThreatAft@ThreatAft

    🚨 getID3 CVE-2026-94106 — CVSS 8.8 A crafted filename is enough. shell_exec() called WITHOUT escapeshellarg(). Affected: through 1.9.25 Fixed: 1.9.26 UPGRADE NOW. → https://threataft.com/articles/getid3-cve-2026-94106-os-command-injection-malicious-filenames #getID3 #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    0000036
    43 followersView on X
  • ADK Cyber@ADKCyber

    CVE-2026-94106 (CVSS 8.8): getID3 <1.9.26 vulnerable to command injection via filenames. Update the library if present in your web or media apps. https://nvd.nist.gov/vuln/detail/CVE-2026-9410… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/6VFS51gPay

    0000034
    96 followersView on X

Explore more