LiveActive security incident?Get immediate response
CVE Record

CVE-2023-39018: FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp....

FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no realistic use cases in which FFmpeg.java uses untrusted input for the path of the executable file.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE describes a disputed code-injection concern in the Java FFmpeg wrapper constructor. The risk depends on whether an application lets untrusted users influence the path to the FFmpeg executable. The public record does not provide CVSS, confirmed exploitation, or a named patch.

Executive priority

Handle as a targeted code-review item, not an emergency, unless your application lets users control FFmpeg executable paths. Prioritize confirming local exposure before allocating patch-window urgency.

Technical view

The reported weakness is unchecked argument handling in net.bramp.ffmpeg.FFmpeg.<constructor>. If the executable path argument were attacker-controlled, unsafe execution could be possible. The CVE record notes multiple third parties dispute realistic exploitability because typical applications do not source this path from untrusted input.

Likely exposure

Likely limited to applications using bramp/ffmpeg-cli-wrapper where the FFmpeg executable path is derived from user, tenant, API, or other untrusted input. Exposure is not established for normal static server-side configuration.

Exploitation context

No source in the bundle reports active exploitation, and the CVE is not in KEV. The issue is explicitly disputed, so treat exploitation assumptions cautiously unless local code shows attacker influence over the constructor path.

Researcher notes

Evidence is thin and disputed. The key research question is data flow into the constructor argument, not generic FFmpeg media parsing. Avoid treating all FFmpeg deployments as affected based on this CVE alone.

Mitigation direction

  • Do not pass user-controlled values into the FFmpeg constructor executable path.
  • Pin the executable path to trusted server-side configuration.
  • Review the upstream GitHub issue and CVE updates for vendor guidance.
  • Apply any upstream fix if one is later published.
  • Document any accepted risk if local usage is static and trusted.

Validation and detection

  • Search code for net.bramp.ffmpeg.FFmpeg constructor usage.
  • Confirm executable path values come only from trusted configuration.
  • Check dependency inventory for bramp ffmpeg-cli-wrapper usage.
  • Review API, job, and tenant inputs for path influence.
  • Record disputed status and absence of KEV evidence.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-39018 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.