HarborGuard / CVE
Back to search
CRITICALCVE-2026-41242Published Modified CNA GitHub_M

CVE-2026-41242: protobufjs has an arbitrary code execution issue

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

Metrics

CVSS v4.0
9.4
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • protobufjs / protobuf.js
    < 7.5.5 · >= 8.0.0-experimental, < 8.0.1
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVE-2026-41242: protobufjs has an arbitrary code execution issue | HarborGuard CVE