CVE-2026-107391: Borewit Music-Metadata
Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.
music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.
Affected products
- Borewit Music-Metadata: before 11.16.0 (fixed in 11.16.0)
Published 2026-10-08. Last modified 2026-10-09.