Intel

AIKIDO-2026-518662

james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Injection

XML External Entity (XXE) InjectionCVE-2026-94108 Published Yesterday

65

Medium Risk

This Affects:

PHPjames-heinrich/getid3
0.0.1 - 1.9.26
Fixed in 1.9.27
Are you affected? Scan for Free

TL;DR

getID3 parses XML metadata such as RIFF/WAV iXML through simplexml_load_string() after calling libxml_disable_entity_loader(true) behind the @ error-suppression operator. On PHP before 8.0 that call can fail silently, leaving external entity resolution enabled for the following parse. A crafted media file whose XML metadata references external entities then reads local files, reaches internal network resources, or exhausts resources through entity expansion. The fix stops suppressing the failure and hardens the XML parser configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run PHP before 8.0 and parse media files whose XML metadata is user controlled.

Background info

james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Injection in versions 0.0.1 - 1.9.26.

How to fix this

Upgrade the james-heinrich/getid3 library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform