Product
getID3 versions prior to 1.9.26 are vulnerable to OS command injection via unescaped shell metacharacters in filenames, allowing for arbitrary command execution.