Command Line Add-On Vulnerability in Protobuf.js by Protobuf
CVE-2026-42290

7.8HIGH

Key Information:

Vendor

Protobufjs

Vendor
CVE Published:
13 May 2026

What is CVE-2026-42290?

The protobufjs-cli tool in Protobuf.js prior to version 1.2.1 and 2.0.2 is susceptible to command injection vulnerabilities. This issue arises from the way pbts constructs shell commands using input file paths, which can lead to the execution of arbitrary commands when malicious input is provided. The vulnerability allows attackers to manipulate the command execution context, potentially leading to unauthorized actions on the system. Users are strongly advised to upgrade to the patched versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

protobuf.js >= 2.0.0, < 2.0.2 < 2.0.0, 2.0.2

protobuf.js < 1.2.1 < 1.2.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.