PT-2026-85582 · Sadtalker · Sadtalker

·

CVE-2026-85696

·

Published

2026-09-04

·

Updated

2026-09-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SadTalker (affected versions not specified)
Description An OS command injection flaw exists in the video muxing process. The application interpolates uploaded audio filenames into ffmpeg commands without proper escaping. An attacker can upload audio files containing shell metacharacters in the filename to bypass quoted arguments and execute arbitrary system commands during video generation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85696

Affected Products

Sadtalker