PT-2026-33607 · Npm · Protobufjs

Published

2026-04-16

·

Updated

2026-05-22

·

CVE-2026-41242

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions protobufjs versions prior to 8.0.1 protobufjs versions prior to 7.5.5
Description This issue involves improper code generation when compiling protobuf definitions into JavaScript functions. Attackers can inject arbitrary code into the 'type' fields of protobuf definitions, which leads to remote code execution during the object decoding process.
Recommendations Update to version 8.0.1. Update to version 7.5.5. Avoid decoding untrusted protobuf definitions.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05548
CVE-2026-41242

Affected Products

Protobufjs