#1148666 php-getid3: CVE-2026-94106

Package:
src:php-getid3
Source:
src:php-getid3
Submitter:
Salvatore Bonaccorso
Date:
2026-09-22 07:07:02 UTC
Severity:
normal
Tags:
#1148666#5
Date:
2026-09-21 18:50:47 UTC
From:
To:
Hi,

The following vulnerability was published for php-getid3.

CVE-2026-94106[0]:
| getID3 before 1.9.26 contains an OS command injection vulnerability
| in shell-out handlers that fail to escape filenames in command
| strings. Attackers can craft malicious filenames containing shell
| metacharacters to inject arbitrary commands executed with the
| privileges of the process embedding getID3.

While it was initially on the Windows only code path, the second
follow up contains as well fixes on the *nix codepath, so filling this
bug.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94106
https://www.cve.org/CVERecord?id=CVE-2026-94106
[1] https://github.com/JamesHeinrich/getID3/issues/503
[2] https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
[3] https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6
[4] https://github.com/JamesHeinrich/getID3/commit/2c6f3f96546f05746405872848114754ed7fe9b4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148666#12
Date:
2026-09-22 07:05:00 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
php-getid3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148666@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
David Prévot <taffit@debian.org> (supplier of updated php-getid3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 22 Sep 2026 08:25:24 +0200
Source: php-getid3
Architecture: source
Version: 1.9.26+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org>
Changed-By: David Prévot <taffit@debian.org>
Closes: 1148666
Changes:
 php-getid3 (1.9.26+dfsg-1) unstable; urgency=medium
 .
   [ Sören Wünsch ]
   * fix: use is_int instead of is_integer for type checking in atom structure
 .
   [ James Heinrich ]
   * PHP8.5 warnings
   * Update getid3.php
   * #503 escapeshellarg [CVE-2026-94106] (Closes: #1148666)
   * v1.9.26-202609042051 changelog
 .
   [ Dan Gravell ]
   * Map RIFF INFO ITRK to track_number (astiga #1294)
 .
   [ Derk-Jan Hartman ]
   * Add JPEG XL (bare codestream) support
   * Add generic ISO Base Media File Format box walker (getid3_isobmff)
   * Guard APE/Lyrics3 scans against negative seeks on tiny files
   * Add JPEG XL ISO BMFF container support
 .
   [ Alan ]
   * clamp ID3v2 frame read to remaining file size
 .
   [ David Prévot ]
   * Replace FSF postal address with a reference to https://www.gnu.org/licenses/
   * Update standards version to 4.7.4
   * Use GitHub template in watch file instead of explicit
     Source/Matching-Pattern
   * Use debhelper-compat 14
Checksums-Sha1:
 38853d19f6aa892325d74e1e686d3e978fb18b0a 1734 php-getid3_1.9.26+dfsg-1.dsc
 03139cc513a1ba59995104b1394c70de69e13713 388140 php-getid3_1.9.26+dfsg.orig.tar.xz
 4d5ce9cd327a8afa379064673a529a8723acb7dd 5764 php-getid3_1.9.26+dfsg-1.debian.tar.xz
 bc935e05e5545872393a9bfacfac97b13254804f 5860 php-getid3_1.9.26+dfsg-1_amd64.buildinfo
Checksums-Sha256:
 c9ef0b3f7273edc894ccf8886f068cab907e90e3576f9dc6bb475cf6de4a0064 1734 php-getid3_1.9.26+dfsg-1.dsc
 265525002b6ef68b4e4566524a337a4f1eee2a6893c5fe869fe5444232b94c25 388140 php-getid3_1.9.26+dfsg.orig.tar.xz
 37bfee00d63ea59cf62e755a8a42b538eb524584893a5e19f1515db150c99aa3 5764 php-getid3_1.9.26+dfsg-1.debian.tar.xz
 7f9c6ac5f19cbbefa8caf4f652f4c03942d6f1a850e291c0ceab58254143d0cf 5860 php-getid3_1.9.26+dfsg-1_amd64.buildinfo
Files:
 409e3327243a833435da79c9849c6321 1734 php optional php-getid3_1.9.26+dfsg-1.dsc
 7f291a2dea676172a4686e16861fab76 388140 php optional php-getid3_1.9.26+dfsg.orig.tar.xz
 f3348c9d3dfcf02159ea229c03a353fe 5764 php optional php-getid3_1.9.26+dfsg-1.debian.tar.xz
 fd23141a8c2d992d67728611bd38d98b 5860 php optional php-getid3_1.9.26+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmqyIyESHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r08qRsIAJxYzGjBhPRXw8DdpwEEqdDZoxUBKB8e
/h8sbS2vx5oqz67X560ZgLJ+QwXVD5CHTQC19TXTpjU7hG1dM+ZSqb1Srpr6x/9L
FtBYxh95Le5gymaeW7Ddztj11urghnWKvDKQUPHW7Emen6p9NJksztzrbWVN00T5
emKpZKOoj1wCI5kJj8zD4+rltB9pX9rUGyFu6TUqNibg/30liN32wqBi+2vD9S2E
MBe5z9hQgwZISIcWvFLAHeCXm9so/BQpZeDYM5zg4qj5gVIHHIqzJm+xXxmZ5vir
aaoqYpJvzW7fIXdIKQi5BWnSGPz9Q36HxO8Mhuw6Lfxz9kwiixPhCYI=
=xfkb
-----END PGP SIGNATURE-----