logo

Cyera Research Uncovers Six Protobuf.js Vulnerabilities Impacting the Backbone of Data and AI Systems

ID: 7c226e0a-c4f7-553f-8b7e-8931326393e3

STIX ID: report--7c226e0a-c4f7-553f-8b7e-8931326393e3

Feed Name: Cyera Blogs

Threat Score
72/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

...
...

Cyera disclosed six vulnerabilities in protobuf.js and protobufjs-cli that can be triggered by malicious protobuf schemas, descriptors, or crafted payloads, potentially resulting in denial-of-service, runtime corruption, or remote code execution. The issues affect many Node.js ecosystems (gRPC toolchains, cloud SDKs, messaging frameworks, CI/CD pipelines, and AI/data stacks) and pose supply-chain and persistent-failure risks (e.g., crashing messaging bots); patches are available (protobufjs 7.5.6/8.0.2 and protobufjs-cli 1.2.1/2.0.2) and immediate mitigation steps are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.