Skip to content
COOEY

EXPOSURES › CVE-2026-41242

CVE-2026-41242

CRITICAL
DETAIL
SourceNVD · cve Published2026-04-18 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-41242 ↗
⚡ RCE ◐ ZERO-DAY SHAME 50/100 rcezero-day

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 an

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.