A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?ctiid.347331 | Permissions Required VDB Entry |
| https://vuldb.com/?id.347331 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.755221 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.755221 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
26 Feb 2026, 20:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/?ctiid.347331 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.347331 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.755221 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:higuma:webaudiorecorder.js:0.1.1:*:*:*:*:*:*:* cpe:2.3:a:higuma:webaudiorecorder.js:0.1:*:*:*:*:*:*:* |
|
| First Time |
Higuma
Higuma webaudiorecorder.js |
23 Feb 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://vuldb.com/?submit.755221 - | |
| Summary |
|
23 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 02:16
Updated : 2026-02-26 20:08
NVD link : CVE-2026-2964
Mitre link : CVE-2026-2964
CVE.ORG link : CVE-2026-2964
JSON object : View
Products Affected
higuma
- webaudiorecorder.js
