XML External Entity Injection in getID3 Media Metadata Handler
CVE-2026-94108
8.3HIGH
What is CVE-2026-94108?
The getID3 media metadata handler prior to version 1.9.26 is susceptible to an XML external entity injection vulnerability due to improper handling of XML metadata. This flaw allows attackers to exploit the XML2array helper function, which fails to disable entity loading in PHP versions earlier than 8.0. By crafting specially designed XML metadata within media files, attackers can potentially disclose sensitive local files, engage in server-side request forgery, or induce denial of service conditions through entity expansion. Adequate mitigation strategies and updates are recommended to safeguard against these risks.
Affected Version(s)
getid3 0 <= 1.9.26
