logo

CVE-2026-1245: Code Injection Flaw Hits Node.js binary-parser

ID: 3228b0c5-b729-51ce-a5f3-e45dbd43c0aa

STIX ID: report--3228b0c5-b729-51ce-a5f3-e45dbd43c0aa

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

The Node.js library "binary-parser" has a critical code-generation flaw (CVE-2026-1245) where unsanitized parser field names and encoding parameters are injected into dynamically generated JavaScript via the Function constructor, enabling arbitrary code execution in applications that build parsers from untrusted input; maintainers have released version 2.3.0 with input validation and mitigations and users are advised to upgrade and avoid using untrusted values in parser definitions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.