Impact
The music‑metadata library contains a flaw in the EBML parser where the length of a VINT element is trusted before checking that its leaf fits within its parent. An attacker can craft WebM, MKV, or MKA files that cause the parser to allocate an oversized string or array, leading to an out‑of‑memory denial of service, or in some runtimes trigger an uncatchable V8 fatal abort. The vulnerability results in a loss of availability for any process that parses untrusted media.
Affected Systems
Vulnerable versions of Borewit music‑metadata fall before 11.16.0. The flaw is present in the Matroska and WebM EBML parsing code used by Node.js applications that import or analyze audio and video files. Environments running Node.js 26.7.0 with the parseFile API show the most severe manifestation of the fault.
Risk and Exploitability
The CVSS score is 6.2, indicating moderate severity. EPSS is not available and there is no current listing in the CISA KEV catalog, so there is no documented exploitation, though the vulnerability can be triggered by supplying a specially crafted media file. The attack vector is likely remote through any interface that accepts untrusted media, but this inference comes from the description; local files can also be used. Exploitation would consume system memory until the process is killed or the runtime aborts, causing a denied service for the affected application.
OpenCVE Enrichment
Github GHSA