Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.6 Node.js & npm GHSA-53v6-4h7p-p4gj CVE-2026-107387

music-metadata: Uncontrolled memory allocation in APEv2 parser (CVE-2026-107387)

An APEv2 parser bug in music-metadata can allocate large buffers based on attacker-controlled tag sizes, causing process memory exhaustion. Fixed in 11.16.0. (CVE-2026-107387, GHSA-53v6-4h7p-p4gj)

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

The npm package music-metadata contains an APEv2 parsing bug that can trigger uncontrolled memory allocation when a tag-item size is attacker-controlled. The issue is tracked as CVE-2026-107387 / GHSA-53v6-4h7p-p4gj and is fixed in 11.16.0. (sources: 4111, 9050, 31887)

What happened

The APEv2 parser in music-metadata reads a tag-item size supplied in the file and allocates a Uint8Array for that binary item before verifying the declared item actually fits in the remaining tag or file data. A small, crafted APE file can therefore cause a disproportionate allocation (for example via a cover-art item). Repeated or concurrent parsing of such files can exhaust process memory. The reported impact is availability loss only. (sources: 4111, 9050, 31887)

Technical cause

The parser uses an attacker-controlled tag-item size to allocate a Uint8Array before performing bounds checks that confirm the declared item fits within the remaining tag or file bytes. This race between allocation and validation allows crafted inputs to force large allocations. (sources: 4111, 9050, 31887)

Why it matters

Successful exploitation leads to process memory exhaustion and availability loss only. The advisory reports a CVSS v3.1 base score of 6.2 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The PatchWire score is 3.6; the CVSS base contributed 3.41 and the 'no user interaction' factor added 0.2. There is no public exploit listed and no claim of known in-the-wild exploitation. (sources: 4111, 9050, 31887)

Who is affected

Projects and services that use music-metadata to parse APEv2 tags are affected, including code paths that accept or process untrusted APE-formatted files (for example cover-art items). The advisory's affected range starts at version 0 and is fixed in 11.16.0. (sources: 4111, 9050, 31887)

Discovery and timeline

The vulnerability record was published on 2026-10-08; source entries include OSV, CVE.org and NVD records with publication times in the package metadata. The advisory metadata shows the issue was fixed in a later release. The fact package does not include information about the original reporter or the detailed discovery timeline. (sources: 4111, 9050, 31887)

Affected versions

The advisory lists the affected range as introduced at 0 and fixed in 11.16.0. Users should treat all releases older than 11.16.0 as affected. (sources: 4111)

Fixes and mitigation

A fix is available; the issue is fixed in 11.16.0. If you cannot immediately update, avoid parsing untrusted APEv2 files or perform input validation/sanitization before handing data to music-metadata. The package metadata does not provide vendor-mandated workarounds beyond the version update. (sources: 4111, 9050, 31887)

Recommended action

Upgrade music-metadata to 11.16.0. If you consume untrusted files and cannot upgrade immediately, mitigate exposure by blocking or validating APEv2 inputs before parsing and by limiting concurrent parsing of untrusted files. Verify transitive dependencies as needed. (sources: 4111, 9050, 31887)

PatchBriefing score

3.6 / 10 · Low

Official CVSS: 6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

The advisory lists a CVSS v3.1 base score of 6.2 (vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). PatchWire's numeric score for this advisory is 3.6; that value is computed from the included factors: the CVSS base contributed 3.41 and the 'no user interaction' factor contributed 0.2, with other factors contributing zero. Do not interpret the PatchWire score as indicating active exploitation — the package records no public exploit and no known in-the-wild exploitation. (sources: 4111, 9050, 31887)

Affected versions

music-metadata ≥ 0 < 11.16.0
vulnerable
≥ 11.16.0
patched

Reported fixes

A fix is available; the issue is fixed in 11.16.0. If you cannot immediately update, avoid parsing untrusted APEv2 files or perform input validation/sanitization before handing data to music-metadata. The package metadata does not provide vendor-mandated workarounds beyond the version update. (sources: 4111, 9050, 31887)

How this was built

3 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • CVE.org database
  • NVD (NIST) database
Unified report
music-metadata: Uncontrolled memory allocation in APEv2 parser (CVE-2026-107387)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email