Critical flaw in Protobuf library enables JavaScript code execution
ID: 49c90200-4e2d-51ec-a517-29a97cac44dd
STIX ID: report--49c90200-4e2d-51ec-a517-29a97cac44dd
Feed Name: Bleeping Computer
A critical remote code execution vulnerability in the widely used protobuf.js JavaScript library (tracked as GHSA-xq3m-2v4x-88gg) allows attackers to inject and execute arbitrary code by supplying malicious protobuf schemas that are turned into dynamic functions via Function(); proof-of-concept exploit code has been published, patches for the 8.x and 7.x branches are available (upgrade to 8.0.1 or 7.5.5), and Endor Labs warns exploitation is straightforward though no active in-the-wild exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
