{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopentalkersadtalker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opentalker:sadtalker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85696"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SadTalker"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenTalker"],"content_html":"\u003cp\u003eSadTalker contains an OS command injection vulnerability (CVE-2026-85696) within its video muxing process. The vulnerability occurs because uploaded audio filenames are directly interpolated into system shell commands (specifically calls to ffmpeg) without appropriate sanitization or escaping. By providing a crafted filename containing shell metacharacters, an unauthenticated attacker can escape the intended shell arguments and execute arbitrary commands on the host operating system with the privileges of the application process. Given that ffmpeg is a standard dependency for video processing, this flaw impacts deployments of SadTalker on any host operating system. Defenders should prioritize identifying instances of this software and ensuring user-supplied filenames are treated as untrusted input.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for unauthenticated remote code execution on the server running the SadTalker application. This can lead to full system compromise, data exfiltration, or the installation of persistent malicious payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict input validation on all user-supplied filenames before passing them to system calls or external binaries.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided security patch or upgrade to the version that remediates CVE-2026-85696 as soon as it becomes available.\u003c/li\u003e\n\u003cli\u003eReview web application logs for POST requests containing unusual characters such as semicolons, ampersands, or pipe operators within file upload parameters.\u003c/li\u003e\n\u003cli\u003eRun the application in a hardened container with minimal filesystem permissions to limit the scope of potential command execution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:57Z","date_published":"2026-09-04T15:26:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sadtalker-rce/","summary":"SadTalker is vulnerable to OS command injection due to improper neutralization of shell metacharacters in uploaded audio filenames during the video muxing process.","title":"OS Command Injection in SadTalker via Filename Interpolation","url":"https://feed.craftedsignal.io/briefs/2026-09-sadtalker-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:opentalker:sadtalker:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}