{"id":"CVE-2026-107388","title":"music-metadata is a metadata parser for audio and video media files","summary":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes.…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-789"],"vendor":"music-metadata","product":"music-metadata","affected":["music-metadata <= 11.12.3"],"patched":["music-metadata 11.16.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:46:35.260","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107388","references":[{"url":"https://github.com/Borewit/music-metadata/commit/b033db675b913a9dba1d29135ec3c10eae7095a7","label":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/pull/2743","label":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","label":"security-advisories@github.com"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-jjpr-9cvf-cq55","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-jjpr-9cvf-cq55"}],"tags":["nvd","ghsa","npm"],"aliases":["GHSA-jjpr-9cvf-cq55"],"ecosystem":"npm","ingestedAt":"2026-10-08T20:06:22.187Z","slug":"CVE-2026-107388","body":"## Overview\n\nmusic-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107388)\n\nAffected packages:\n\n- `music-metadata <= 11.12.3`\n\nPatched in:\n\n- `music-metadata 11.16.0`\n\nSource: https://github.com/advisories/GHSA-jjpr-9cvf-cq55","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}