Command Line Add-On Vulnerability in Protobuf.js by Protobuf
CVE-2026-42290
7.8HIGH
What is CVE-2026-42290?
The protobufjs-cli tool in Protobuf.js prior to version 1.2.1 and 2.0.2 is susceptible to command injection vulnerabilities. This issue arises from the way pbts constructs shell commands using input file paths, which can lead to the execution of arbitrary commands when malicious input is provided. The vulnerability allows attackers to manipulate the command execution context, potentially leading to unauthorized actions on the system. Users are strongly advised to upgrade to the patched versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
protobuf.js >= 2.0.0, < 2.0.2 < 2.0.0, 2.0.2
protobuf.js < 1.2.1 < 1.2.1
