CVE-2026-25713: Mediaarea Mediainfolib
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted media file that contains ID3v2 tags can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected products
- Mediaarea Mediainfolib: version 26.01 only
Published 2026-05-26. Last modified 2026-09-23.