Gpac · Gpac · CVE-2026-1415
**Name of the Vulnerable Software and Affected Versions**
GPAC versions up to 2.4.0
**Description**
A flaw exists in GPAC where manipulation of the `Name` argument within the `gf media export webvtt metadata` function, located in the `src/media tools/media export.c` file, can lead to a null pointer dereference. This issue requires local access to exploit. The exploit is publicly available.
**Recommendations**
Deploy the patch with identifier af951b892dfbaaa38336ba2eba6d6a42c25810fd.