Answer in brief
CVE-2026-107389 records a Medium severity (CVSS 6.2) vulnerability in music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort. The current sources do not mark it as known exploited. The current feed maps Borewit/music-metadata (generic), music-metadata (npm). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Borewit/music-metadata (generic), music-metadata (npm). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Borewit/music-metadatageneric | <11.16.0 | 11.16.0 |
| music-metadatanpm | <11.16.0 | 11.16.0 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.
Quoted source text, attributed separately from HOL analysis.