Juce is an audio and graphics application framework widely embedded in digital audio workstations and music production software, with its vulnerability profile concentrated around path-traversal and improper link-resolution issues in file-handling operations. These weakness classes reflect the file-system access patterns inherent to a multimedia development library; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Juce over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23520CRITICAL The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. | Jan 31, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-23521HIGH This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containing a symbolic link. When extrac | Jan 31, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Juce.
Media articles that mention a CVE ID that affects a product developed by Juce — matched by CVE ID, not by vendor name.