james-heinrich/getid3 is vulnerable to OS Command Injection
88
High Risk
getID3 shells out to bundled Windows helper executables such as vorbiscomment.exe and shorten.exe to read or write certain tags, building the command line by concatenating the target file path inside double quotes. The path is passed to shell_exec() without escaping, so a filename containing shell metacharacters injects additional commands that run with the PHP process privileges. Reaching the sink requires the external helper applications to be configured through GETID3_HELPERAPPSDIR on Windows and a user controlled filename. The fix wraps every path argument in escapeshellarg().
You are affected if you are using a version that falls within the vulnerable range and you run getID3 on Windows with the optional external helper applications enabled and analyze or write tags for files whose path is user controlled.
james-heinrich/getid3 is vulnerable to OS Command Injection in versions 1.9.8 - 1.9.25.
Upgrade the james-heinrich/getid3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.