PT-2026-108150 · Npm · Music-Metadata
CVE-2026-107387
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
music-metadata versions prior to 11.16.0
Description
The APEv2 parser in music-metadata contains an issue where it reads a tag-item size controlled by an attacker and allocates a
Uint8Array for a binary item before verifying if the declared size fits within the remaining tag or file data. A small, specially crafted APE file can trigger a disproportionate memory allocation, particularly through cover-art items. Repeated or concurrent parsing of such files can lead to memory exhaustion, resulting in a denial of service and loss of availability.Recommendations
Update to version 11.16.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Music-Metadata