OS Command Injection Vulnerability in SadTalker by OpenTalker
CVE-2026-85696
9.3CRITICAL
What is CVE-2026-85696?
SadTalker, developed by OpenTalker, is susceptible to an OS command injection flaw in its video muxing process. This vulnerability arises when uploaded audio filenames, which may contain shell metacharacters, are not properly escaped before being incorporated into ffmpeg commands. Attackers can exploit this weakness by uploading malicious audio files, allowing them to execute arbitrary system commands during the video generation phase. This security concern highlights the need for stringent input validation and command execution practices.
Affected Version(s)
SadTalker 0 <= 0.0.2
