logo

Node.js binary-parser Library Flaw Enables Malicious Code Injection

ID: 403ccd33-d7ef-5c5b-afcb-f3b9f484c310

STIX ID: report--403ccd33-d7ef-5c5b-afcb-f3b9f484c310

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-05-11

Author: Varshini

...
...

CERT/CC published VU#102648 for CVE-2026-1245: a critical code-injection vulnerability in binary-parser (pre-2.3.0) where the library’s use of the Function constructor to generate parser code from untrusted inputs allows remote arbitrary JavaScript execution; users should immediately upgrade to 2.3.0+, audit dynamic parsers, and monitor Node.js runtimes for anomalous new Function() usage or unexpected child processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.