CVE-2026-90684: GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion
A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gfnodegetfieldcount of the file scenegraph/basescenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running GPAC MP4Box with versions up to f1219cde are affected. Exploitation requires local-host access and low privileges.
What does an attacker need to do to exploit it?
An attacker must perform a manipulation that reaches an assertion in gf_node_get_field_count in scenegraph/base_scenegraph.c. User interaction is also required according to the supplied severity vector.
What is the likely impact?
The reachable assertion can cause an availability impact. The supplied vector indicates no confidentiality or integrity impact and a low availability impact.
Is public exploit information available?
Yes. The exploit has been published and may be used.
What should be done to remediate the issue?
Upgrade GPAC MP4Box to version abi-16.23. The stated fix is patch 49dee5cad329cfed310c1682703df7daa47df31a.