Impact
The vulnerability originates from a use‑after‑free in the gf_node_get_name_and_id function located in scenegraph/base_scenegraph.c. The flaw (CWE‑416) allows an attacker to read or write memory after it has been freed, potentially enabling arbitrary code execution or data leakage (CWE‑119). Because the function can be invoked remotely, a malicious actor can supply crafted input to trigger the freed memory usage, leading to compromise of confidentiality, integrity, or availability.
Affected Systems
The issue affects GPAC releases up to commit f1219cde, including any distribution before the abi‑16.23 tag. Users running the open‑source GPAC library without applying the 49dee5cad329cfed310c1682703df7daa47df31a patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the moment. The exploit is publicly available and can be triggered remotely, so attackers could target sensitive deployments. It is not listed in the CISA KEV catalog, but the public nature of the exploit and remote trigger elevate the risk relative to the low EPSS score.
OpenCVE Enrichment