CVE-2026-47114 – iina

CVSS 8.8 IMPORTANT

“Command injection weaknesses in media applications can turn simple user interaction into a serious security event.”

A patch was released for a high-severity vulnerability affecting iina. CVE-2026-47114 has a CVSS score of 8.8, which is High severity.

The vulnerability involves improper argument neutralization handling that could allow attackers to manipulate command execution behavior in affected environments. Public proof-of-concept code is available. The update strengthens input handling protections and reduces the risk of unauthorized command execution through crafted interaction paths.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-88
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.