logo

220 Million at Risk: Critical 9.4 CVSS Remote Code Execution Hits protobuf.js

ID: 18f9ceeb-234c-5a7a-bf5e-5b3462aa4117

STIX ID: report--18f9ceeb-234c-5a7a-bf5e-5b3462aa4117

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical arbitrary code execution vulnerability (CVSS 9.4) in the protobuf.js library allows attackers to inject JavaScript into protobuf/JSON descriptor "type" fields so that executing UserType.decode() runs the injected code; a PoC demonstrates command execution (e.g., id). Widely used across Node.js and browser apps, affected versions include protobuf.js 8.0.0 and earlier (8.x line) and 7.5.4 and earlier (7.x line); developers are urged to audit dependencies and update to patched versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.