← Back to search

CVE-2026-88365

9.8 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-29

AI risk analysis

Summary
The flaw is an integer overflow vulnerability in the mp3dec_skip_id3v1() function when parsing the APEv2 tag-size field, which can lead to arbitrary code execution. This matters because attackers can exploit it to execute malicious code, leading to severe system compromise.
Exploitability
Exploiting this vulnerability is relatively easy given the critical severity and the presence of a public exploit. The attacker needs to craft a specially crafted MP3 file containing an APEv2 tag with an oversized size field.
Blast radius
If exploited, this vulnerability could result in complete system compromise, allowing attackers to execute arbitrary code with the privileges of the user running the vulnerable application.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected mp3dec functionality or upgrade to the version containing the fix, such as 'Upgrade to the version containing the fix for CVE-2026-88365 or later'.
rcefile-formataudiocritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.