PT-2026-108170 · Npm · Music-Metadata

CVE-2026-107390

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions music-metadata versions prior to 11.16.0
Description The MP4 parser accepts an attacker-controlled 64-bit extended atom size and converts it to a JavaScript Number. This resulting payload length is used for atom-specific readToken() calls before verifying if the atom fits within its parent or the available input. A small MP4-family file can trigger an oversized length during payload parsing for atoms such as mvhd, stsd, stsz, and date, leading to a large memory allocation attempt or process failure. This can result in a denial of service for applications parsing untrusted MP4-family media.
Recommendations Update to version 11.16.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107390

Affected Products

Music-Metadata