Node.js binary-parser Library Flaw Enables Malicious Code Injection
ID: 403ccd33-d7ef-5c5b-afcb-f3b9f484c310
STIX ID: report--403ccd33-d7ef-5c5b-afcb-f3b9f484c310
Feed Name: GBHackers
Threat Score
CERT/CC published VU#102648 for CVE-2026-1245: a critical code-injection vulnerability in binary-parser (pre-2.3.0) where the library’s use of the Function constructor to generate parser code from untrusted inputs allows remote arbitrary JavaScript execution; users should immediately upgrade to 2.3.0+, audit dynamic parsers, and monitor Node.js runtimes for anomalous new Function() usage or unexpected child processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
