music-metadata, Uncatchable Process Crash, CVE-2026-107392 (Moderate) -DC-Oct2026-2954

Listen to this Post

The CVE-2026-107392 vulnerability in music-metadata stems from an un-awaited asynchronous method call within the DSF parser’s main chunk iteration loop.
Specifically, inside lib/dsf/DsfParser.js, the parseChunks routine processes incoming media stream blocks via a tokenizer instance.
When an unrecognized chunk is encountered—where the chunk identifier is not equal to ‘fmt ‘—the parser calculates the payload skip offset.
If a malicious actor crafts a DSF file with a chunk size header smaller than the 12-byte ChunkHeader length, the resulting subtraction produces a negative integer.
The code then passes this negative value directly into this.tokenizer.ignore() without awaiting the returned promise.
Because strtok3 versions 10.3.5 and above strictly throw a RangeError when given a negative ignore length, this un-awaited invocation rejects.
Due to the missing await keyword, the rejection becomes entirely detached from the parseBuffer promise chain, manifesting as an unhandled promise rejection.
In Node.js runtimes version 15 and higher, unhandled promise rejections default to terminating the process immediately.
Crucially, this crash occurs after parseBuffer has already completed its synchronous execution or resolved, meaning standard caller-side try/catch blocks are powerless to intercept it.
Consequently, an attacker can supply a single malformed audio file to crash server processes or worker threads reliably, creating an uncatchable Denial of Service condition across applications parsing untrusted media.

DailyCVE Form:

Platform: music-metadata
Version: Before 11.15.0
Vulnerability: Uncatchable Process Crash
Severity: Moderate
Date: October 2026

Prediction: Patched in 11.15.0

What Undercode Say:

To analyze and reproduce the vulnerability in your local environment, use the following bash commands and script setup:

npm install [email protected]
mkdir repro && cd repro

PoC reproduction code (`poc.mjs`):

import { parseBuffer } from 'music-metadata';
const maliciousBuffer = Buffer.from([
0x44, 0x53, 0x44, 0x20, // 'DSD ' magic
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x10, // Chunk header
0x42, 0x41, 0x44, 0x5a, // Unrecognized chunk ID != 'fmt '
0x01, 0x00, 0x00, 0x00 // Size = 1st byte (< 12)
]);
try {
const result = await parseBuffer(maliciousBuffer);
console.log('[bash] parseBuffer() RESOLVED — caller saw no error:', result);
} catch (err) {
console.log('[bash] Caught error:', err);
}
setTimeout(() => {
console.log('[bash] Process survived (this line never prints due to crash).');
}, 1000);

Run the proof-of-concept:

node poc.mjs

How Exploit: (Educational Purposes!)

The exploit vector relies on submitting an untrusted audio file bearing the DSD magic bytes (DSD) alongside a custom crafted chunk header whose size field is set between 0 and 11 bytes (less than the 12-byte ChunkHeader.len). When `DsfParser.parseChunks` processes this block, the subtraction of `ChunkHeader.len` (12) from the malformed size results in a negative integer. Passing this negative value into `tokenizer.ignore()` triggers a `RangeError` from the underlying `strtok3` library. Because the parser developer omitted the `await` keyword before this.tokenizer.ignore(), the resulting exception is emitted as an unhandled promise rejection rather than a synchronous or catchable asynchronous error. In modern Node.js runtimes (v15+), unhandled rejections terminate the process immediately, bypassing any try/catch wrappers implemented by consuming applications.

Protection: from this CVE

To protect applications against CVE-2026-107392, maintainers must upgrade `music-metadata` to version 11.15.0 or higher. If patching immediately is not feasible, ensure that input files from untrusted sources are strictly validated for structural integrity and minimum chunk sizes before being passed to parsing functions. Furthermore, application environments can register global process listeners for `unhandledRejection` to prevent abrupt process termination, although upgrading the dependency remains the definitive remediation.

Impact:

This vulnerability causes a high-availability Denial of Service (DoS) affecting any Node.js application processing untrusted audio files using vulnerable versions of `music-metadata` (which receives over 2.2 million weekly downloads). Because the crash evades standard caller-side `try/catch` error handling blocks, a single malicious file upload can take down shared server processes, worker threads, or microservices, impacting system availability across web platforms and media servers.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top