Code Execution Vulnerability in Protobuf.js by ProtobufJS
CVE-2026-41242

9.4CRITICAL

Key Information:

Vendor

Protobufjs

Vendor
CVE Published:
18 April 2026

What is CVE-2026-41242?

Protobuf.js, a library that compiles protocol buffer definitions into JavaScript functions, is susceptible to a vulnerability that enables attackers to inject arbitrary code via the 'type' fields in protobuf definitions. This injected code can be executed during the decoding of the corresponding objects. The vulnerability affects versions prior to 8.0.1 and 7.5.5, both of which contain patches to mitigate the risk.

Affected Version(s)

protobuf.js < 7.5.5 < 7.5.5

protobuf.js >= 8.0.0-experimental, < 8.0.1 < 8.0.0-experimental, 8.0.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.