DSF Parsing Vulnerability in music-metadata by Borewit
CVE-2026-107392
6.2MEDIUM
What is CVE-2026-107392?
The music-metadata library, a metadata parser for audio and video files, contains a vulnerability affecting the DSF parser prior to version 11.15.0. This flaw arises when unrecognized chunks are processed, leading to a potential negative ignore length due to the improper handling of asynchronous promises. Specifically, a crafted DSF input can trigger a RangeError that escapes usual error handling via try/catch blocks, ultimately resulting in a process crash. This could lead to availability loss in applications utilizing the DSF parsing functionality. The issue is resolved in version 11.15.0.
Affected Version(s)
music-metadata < 11.15.0
