๐Ÿ” CVE Alert

CVE-2026-107391

MEDIUM 6.2

music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) โ€” unreleased regression on master

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.

CWE CWE-400 CWE-835
Vendor borewit
Product music-metadata
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for borewit music-metadata

Be the first to know when new medium vulnerabilities affecting borewit music-metadata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Borewit / music-metadata
< 11.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Borewit/music-metadata/security/advisories/GHSA-f94x-6692-553q github.com: https://github.com/Borewit/music-metadata/pull/2734 github.com: https://github.com/Borewit/music-metadata/commit/90a7d52c69e921a0b019592d887acd97b1c8b8a5 github.com: https://github.com/Borewit/music-metadata/releases/tag/v11.16.0