CVE-2023-39018

CRITICAL

bramp/ffmpeg-cli-wrapper < 0.7.0 - Code Injection via Unchecked Argument

Title source: llm
STIX 2.1

Description

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.

Scores

CVSS v3 9.8
EPSS 0.0078
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
bramp/ffmpeg-cli-wrapper < 0.7.0
net.bramp.ffmpeg/ffmpeg 0Maven
Published Jul 28, 2023
Tracked Since Feb 18, 2026