Impact
msgpack5 decodes negative signed 64-bit integers by modifying the caller’s input buffer while computing the value. As a result, any data that contains such values becomes corrupted in the original buffer, which can silently break integrity checks, logging or subsequent processing. Positive integers and other data types are unaffected. The vulnerability is a data corruption flaw (CWE-471).
Affected Systems
The msgpack5 library, maintained by mcollina, is affected when used in Node.js or web browser environments. All released versions prior to 6.1.0 are vulnerable; version 6.1.0 and later contain the fix.
Risk and Exploitability
The CVSS score of 3.7 indicates low to moderate severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. The attack vector is likely same-user or local application code that feeds data to msgpack5, as the flaw requires the ability to supply arbitrary input containing negative int64 values. The impact is silent data corruption rather than denial of service or code execution, but for applications that rely on data integrity it can have significant operational consequences.
OpenCVE Enrichment
Github GHSA