james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Injection
65
Medium Risk
getID3 parses XML metadata such as RIFF/WAV iXML through simplexml_load_string() after calling libxml_disable_entity_loader(true) behind the @ error-suppression operator. On PHP before 8.0 that call can fail silently, leaving external entity resolution enabled for the following parse. A crafted media file whose XML metadata references external entities then reads local files, reaches internal network resources, or exhausts resources through entity expansion. The fix stops suppressing the failure and hardens the XML parser configuration.
You are affected if you are using a version that falls within the vulnerable range and you run PHP before 8.0 and parse media files whose XML metadata is user controlled.
james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Injection in versions 0.0.1 - 1.9.26.
Upgrade the james-heinrich/getid3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.