CVE-2026-90685Low· 2.8▾ TwilightPoC availableA vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 15.4 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
Exploit / PoC code exists
A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90611Low· 3.3A vulnerability was determined in GPAC up to f1219cde
CVE-2026-90612Low· 3.3A vulnerability was identified in GPAC up to f1219cde
CVE-2026-91088Medium· 4.8A vulnerability has been found in GPAC up to f1219cde
CVE-2026-91086Medium· 6.3A security vulnerability has been detected in GPAC up to f1219cde
CVE-2026-90826Low· 2.8A vulnerability was determined in GPAC 26.07.0
CVE-2026-90610Low· 3.3A vulnerability was found in GPAC up to f1219cde