SadTalker npm Package OS Command Injection Vulnerability Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- sadtalker (npm)
- Affected versions
- >= v0.0.2, <= v0.0.2 or >= v0.0.1, <= v0.0.1
- Patched version
- Not yet available
An OS command injection vulnerability has been reported in the SadTalker npm package. Users of versions 0.0.1 and 0.0.2 are advised to take immediate action.
What happened
An OS command injection vulnerability has been identified in the SadTalker npm package. The vulnerability lies in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. This allows attackers to upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands during video generation.
The vulnerability affects SadTalker npm package versions 0.0.1 and 0.0.2. No patched version has been released yet. It is recommended to avoid using SadTalker until a fix is available and to rotate any secrets in affected environments.
What to do about it
- Stop using SadTalker npm package versions 0.0.1 and 0.0.2 immediately.
- Rotate any secrets or credentials in environments where SadTalker was deployed.
- Monitor the sources below for updates on a patched version.
- Consider alternative packages for video muxing until SadTalker is patched.
How 0Day would have caught this
sadtalker is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using SadTalker npm package versions 0.0.1 or 0.0.2.
What should I do right now?
Stop using SadTalker and rotate any secrets in affected environments. Monitor the sources for updates on a patched version.
Is there a patched version available?
No official fix has been published yet. Monitor the sources for updates.
Where can I find more information?
Consult the primary sources listed below for the latest information.