PT-2026-108150 · Npm · Music-Metadata

CVE-2026-107387

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions music-metadata versions prior to 11.16.0
Description The APEv2 parser in music-metadata contains an issue where it reads a tag-item size controlled by an attacker and allocates a Uint8Array for a binary item before verifying if the declared size fits within the remaining tag or file data. A small, specially crafted APE file can trigger a disproportionate memory allocation, particularly through cover-art items. Repeated or concurrent parsing of such files can lead to memory exhaustion, resulting in a denial of service and loss of availability.
Recommendations Update to version 11.16.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107387
GHSA-53V6-4H7P-P4GJ

Affected Products

Music-Metadata