220 Million at Risk: Critical 9.4 CVSS Remote Code Execution Hits protobuf.js
ID: 18f9ceeb-234c-5a7a-bf5e-5b3462aa4117
STIX ID: report--18f9ceeb-234c-5a7a-bf5e-5b3462aa4117
Feed Name: securityonline.info
A critical arbitrary code execution vulnerability (CVSS 9.4) in the protobuf.js library allows attackers to inject JavaScript into protobuf/JSON descriptor "type" fields so that executing UserType.decode() runs the injected code; a PoC demonstrates command execution (e.g., id). Widely used across Node.js and browser apps, affected versions include protobuf.js 8.0.0 and earlier (8.x line) and 7.5.4 and earlier (7.x line); developers are urged to audit dependencies and update to patched versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
