EXPOSURES › CVE-2026-41242
CVE-2026-41242
CRITICAL
DETAIL
SourceNVD · cve
Published2026-04-18
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-41242 ↗
⚡ RCE
◐ ZERO-DAY
SHAME 50/100
rcezero-day
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 an
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.