Vulnerabilities/

music-metadata has an infinite loop vulnerability in ASF parser

Severity:
High

Description

music-metadata’s ASF parser (parseExtensionObject() in lib/asf/AsfParser.ts:112-158) enters an infinite loop when a sub-object inside the ASF Header Extension Object has objectSize = 0.

Recommendation

Update the music-metadata package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
music-metadata
Anything's wrong? Let us know Last updated on March 19, 2026