music-metadata 是一个用于解析音视频媒体文件元数据的库。在版本 11.16.0 之前,其 MP4 解析器会接受攻击者可控的 64 位扩展原子(atom)大小,并将其转换为 JavaScript 的 Number 类型,随后在未验证该原子是否位于其父容器内或是否超出可用输入数据范围的情况下,直接使用计算出的负载长度进行与原子类型相关的 readToken 读取操作。这种缺陷使得一个极小的 MP4 系列文件能够将过大的长度值引入到对 mvhd、stsd、stsz 和 date 等原子的负载解析中,从而在到
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107387 | 6.2 MEDIUM | music-metadata: Uncontrolled memory allocation in APEv2 parser |
| CVE-2026-107388 | 6.2 MEDIUM | music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion |
| CVE-2026-107389 | 6.2 MEDIUM | music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process |
| CVE-2026-107392 | 6.2 MEDIUM | music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3 |
| CVE-2026-107391 | 6.2 MEDIUM | music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u |
No comments yet