SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentalker
Opentalker sadtalker |
|
| Vendors & Products |
Opentalker
Opentalker sadtalker |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs. | |
| Title | SadTalker OS Command Injection via Audio Filename | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T14:32:38.799Z
Updated: 2026-09-04T14:32:38.799Z
Reserved: 2026-09-04T13:51:52.250Z
Link: CVE-2026-85696
No data.
Status : Received
Published: 2026-09-04T15:17:48.523
Modified: 2026-09-04T15:17:48.523
Link: CVE-2026-85696
No data.