CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-41242

Critical · CVSS 9.8

protobuf.js (protobufjs) — Code Injection via protobuf definition "type" field (CWE-94)

CVSS
9.8
nvd
EPSS
0.74%
50th pct
KEV
No
Class
oss containerizable
CWE-94, CWE-94

Description

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

Search profile — drives PoC discovery

Symbols typedecodeprotobuf definitionscompilesJavaScript functionsobject decodingGHSA-xq3m-2v4x-88gg535df444ac060243722ac5d672db205e5c531d75ff7b2afef8754837cc6dc64c864cd111ab477956
Keywords CVE-2026-41242protobufjs code injectionprotobuf.js type field injectionprotobufjs arbitrary code executionprotobufjs decode exploitGHSA-xq3m-2v4x-88ggprotobufjs 7.5.5 8.0.1 patchprotobuf definition injection PoC
Versions: < 7.5.5 (v7.x branch), < 8.0.1 (v8.x branch)

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

npm protobufjs 0 → 7.5.5
npm protobufjs 8.0.0 → 8.0.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z