Back to database
Soon62Medium6.2VulnerabilityCVE-2026-107390No patch link observed

CVE-2026-107390 — music-metadata is a metadata parser for audio and video media files.

Published Oct 8, 2026, 08:17 PM UTCIngested 1h agoSource NVD(cve-db)CVE-2026-107390

Description

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.

CVSS v3.1 base metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
6.2

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Local

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability