Impact
In music-metadata’s APEv2 parser, an attacker‑controlled tag‑item size is read before confirming that the item fits within the remaining tag or file data. This oversight allows a disproportionately large Uint8Array to be allocated, leading to memory exhaustion and application crashes. The vulnerability manifests only as availability loss and is classified as CWE‑789, uncontrolled memory allocation.
Affected Systems
Any use of Borewit’s music-metadata library prior to version 11.16.0 is affected. The fix applied in v11.16.0 verifies tag sizes before allocation, eliminating the dangerous memory growth. Systems that parse user‑supplied or third‑party media files with this library—such as Node.js applications or media players—must review their dependency versions.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. EPSS data is not available, and the issue is not listed in CISA KEV. An attacker can exploit the flaw simply by providing a crafted APE file containing oversized tag items; no additional privileges or code execution are required. Successful exploitation leads to total application interruption through memory exhaustion, but it does not impact confidentiality or integrity.
OpenCVE Enrichment
Github GHSA