XML External Entity Injection in getID3 Media Metadata Handler
CVE-2026-94108

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-94108?

The getID3 media metadata handler prior to version 1.9.26 is susceptible to an XML external entity injection vulnerability due to improper handling of XML metadata. This flaw allows attackers to exploit the XML2array helper function, which fails to disable entity loading in PHP versions earlier than 8.0. By crafting specially designed XML metadata within media files, attackers can potentially disclose sensitive local files, engage in server-side request forgery, or induce denial of service conditions through entity expansion. Adequate mitigation strategies and updates are recommended to safeguard against these risks.

Affected Version(s)

getid3 0 <= 1.9.26

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.