Vulnerability in MP4 StsdAtom Parser Affects Music Metadata by Borewit
CVE-2026-107391

6.2MEDIUM

Key Information:

Vendor

Borewit

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107391?

A vulnerability in the music-metadata library's MP4 sample-description parser allows crafted MP4 input files to manipulate the event loop, potentially leading to memory exhaustion or process termination. This issue arises from a regression that enables an attacker to control sample-entry sizes. The problem persists in versions after 11.14.0 and can be mitigated by upgrading to version 11.16.0, where the vulnerability has been addressed.

Affected Version(s)

music-metadata < 11.16.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.