Code Execution Vulnerability in Protobuf.js by ProtobufJS
CVE-2026-41242
Key Information:
- Vendor
Protobufjs
- Status
- Vendor
- CVE Published:
- 18 April 2026
Badges
What is CVE-2026-41242?
Protobuf.js, a library that compiles protocol buffer definitions into JavaScript functions, is susceptible to a vulnerability that enables attackers to inject arbitrary code via the 'type' fields in protobuf definitions. This injected code can be executed during the decoding of the corresponding objects. The vulnerability affects versions prior to 8.0.1 and 7.5.5, both of which contain patches to mitigate the risk.
Affected Version(s)
protobuf.js < 7.5.5 < 7.5.5
protobuf.js >= 8.0.0-experimental, < 8.0.1 < 8.0.0-experimental, 8.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
