CVE-2026-47114
8.8 HIGHIINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by ...
Published: 2026-05-21 · Last updated: 2026-05-21
Severity and scoring
- CVSS
- 8.8 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-88
Description
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command execution as the current macOS user upon approval of the browser protocol prompt without requiring a valid media file.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-47114
- [Other]https://binary.stackpointer.re/iina-142-url-scheme-command-execution
- [Other]https://github.com/iina/iina/commit/1e6f43248dab9d6ae303781c790e5315cbc9fcef
- [Other]https://github.com/iina/iina/releases/tag/v1.4.3
- [Other]https://www.vulncheck.com/advisories/iina-command-execution-via-iina-open-url-scheme
Related CVEs
Same CWE
- CVE-2026-47365 — Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass ... (9.9 CRITICAL)
- CVE-2026-47250 — mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management (6.1 MEDIUM)
- CVE-2026-46529 — Atril Document Viewer is the default document reader of the MATE desktop environment for Linux
- CVE-2026-53694 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.T...
- CVE-2026-52750 — Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not ... (7.8 HIGH)