52M-Download protobuf.js Library Hit by RCE in Schema Handling
ID: 0654fa36-75d2-5bd5-b4a6-4d7af55aa4bc
STIX ID: report--0654fa36-75d2-5bd5-b4a6-4d7af55aa4bc
Feed Name: HackRead
Threat Score
**Endor Labs discovered a critical RCE vulnerability (GHSA-xq3m-2v4x-88gg, CVSS 9.4) in protobuf.js allowing attacker-controlled schema names to be turned into executable code via the Function constructor; affected versions include 8.0.0 and earlier and 7.5.4 and earlier, and fixes are available in 8.0.1 and 7.5.5 — organisations relying on untrusted or user-uploaded schemas (e.g., gRPC reflection or multi-tenant systems) should immediately patch to mitigate trivial exploitation.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
