Product
SadTalker is vulnerable to OS command injection due to improper neutralization of shell metacharacters in uploaded audio filenames during the video muxing process.