CVE-2026-47114
IINA < 1.4.3 Command Execution via iina://open URL Scheme
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.6EPSS 0.7%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
21 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command execution as the current macOS user upon approval of the browser protocol prompt without requiring a valid media file.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
iina · iinapublic PoCs found — 1
cve_referencebinary.stackpointer.re/iina-142-url-scheme-command-executionunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →