Impact
music-metadata is a Node.js library used to extract metadata from audio and video files. A regression introduced after 11.14.0 in the MP4 stsd sample-description parser allows an attacker to craft a sample-entry with a size of zero. This prevents the internal cursor from advancing while an attacker-controlled entry_count keeps a synchronous loop running, which blocks the Node.js event loop and can grow the sample-description table until the process is terminated or memory is exhausted. The resulting denial of service is the primary impact.
Affected Systems
The vulnerability resides in the Borewit:music-metadata package. Any Node.js project that relies on a version earlier than 11.16.0 and processes MP4-family files is affected. The regression was present in the public master branch but did not appear in releases up to 11.14.0. The fix is included in release 11.16.0 and subsequent versions.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is currently unavailable, so the exploitation probability is unknown. An attacker can exploit this by delivering a malicious MP4 file either locally or through a media ingestion endpoint. While no remote code execution is possible, the denial‑of‑service nature can disrupt services or deplete memory resources, making it a noteworthy concern for applications that handle user‑supplied media.
OpenCVE Enrichment
Github GHSA