CVE-2026-47114 Details
Description
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command execution as the current macOS user upon approval of the browser protocol prompt without requiring a valid media file.
A command execution vulnerability has been identified in IINA versions prior to 1.4.3 for macOS. This vulnerability allows remote attackers to execute arbitrary commands by sending malicious query parameters prefixed with 'mpv_' through the 'iina://open' URL scheme. The application forwards these unvalidated parameters into the mpv runtime, enabling command execution as the current macOS user, after the user approves a browser prompt. Notably, this vulnerability does not require a valid media file.
Users can update to IINA version 1.4.3, which addresses this vulnerability by rejecting 'mpv_' query parameters that could be used for command execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2026CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://binary.stackpointer.re/iina-142-url-scheme-command-execution | [email protected] | ExploitTechnical Analysis |
| https://github.com/iina/iina/commit/1e6f43248dab9d6ae303781c790e5315cbc9fcef | [email protected] | Source CodeVendor |
| https://github.com/iina/iina/releases/tag/v1.4.3 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/iina-command-execution-via-iina-open-url-scheme | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| IINA | < 1.4.3 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | New CVE Received | [email protected] |
Volerion