{"id":"CVE-2023-39018","details":"FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.\u003cconstructor\u003e. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.","modified":"2026-08-12T03:51:23.361322428Z","published":"2023-07-28T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39018.json","cna_assigner":"mitre","isDisputed":true},"references":[{"type":"WEB","url":"https://github.com/bramp/ffmpeg-cli-wrapper/blob/master/src/main/java/net/bramp/ffmpeg/FFmpeg.java"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39018.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39018"},{"type":"REPORT","url":"https://github.com/bramp/ffmpeg-cli-wrapper/issues/291"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bramp/ffmpeg-cli-wrapper","events":[{"introduced":"0"},{"last_affected":"577a8daa7d18735f7ada321d3f40bf984426332e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:bramp:ffmpeg-cli-wrapper:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.7.0"}]}}],"versions":["ffmpeg-0.7.0","ffmpeg-0.6.2","ffmpeg-0.6.1","ffmpeg-0.6","ffmpeg-0.5","ffmpeg-0.4","ffmpeg-0.3","ffmpeg-0.2","ffmpeg-0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39018.json"}}],"schema_version":"1.9.0"}