CVE-2026-41242
Critical · CVSS 9.8protobuf.js (protobufjs) — Code Injection via protobuf definition "type" field (CWE-94)
- CVSS
- 9.8
- nvd
- EPSS
- 0.74%
- 50th pct
- KEV
- No
- Class
- oss containerizable
- CWE-94, CWE-94
Description
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
Search profile — drives PoC discovery
Symbols typedecodeprotobuf definitionscompilesJavaScript functionsobject decodingGHSA-xq3m-2v4x-88gg535df444ac060243722ac5d672db205e5c531d75ff7b2afef8754837cc6dc64c864cd111ab477956
Keywords CVE-2026-41242protobufjs code injectionprotobuf.js type field injectionprotobufjs arbitrary code executionprotobufjs decode exploitGHSA-xq3m-2v4x-88ggprotobufjs 7.5.5 8.0.1 patchprotobuf definition injection PoC
Versions: < 7.5.5 (v7.x branch), < 8.0.1 (v8.x branch)
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| npm | protobufjs | 0 → 7.5.5 |
| npm | protobufjs | 8.0.0 → 8.0.1 |
References
- https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75
- https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg
- https://access.redhat.com/errata/RHSA-2026:21338
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:26234
- https://access.redhat.com/errata/RHSA-2026:37275
- https://access.redhat.com/security/cve/CVE-2026-41242
- https://bugzilla.redhat.com/show_bug.cgi?id=2459442
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z