CVE-2026-47114

IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command execution as the current macOS user upon approval of the browser protocol prompt without requiring a valid media file.
Configurations

No configuration.

History

21 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 20:16

Updated : 2026-05-21 21:03


NVD link : CVE-2026-47114

Mitre link : CVE-2026-47114

CVE.ORG link : CVE-2026-47114


JSON object : View

Products Affected

No product.

CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')