CVE-2026-41242: Protobufjs Project Protobufjs

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

Affected products

Published 2026-04-18. Last modified 2026-09-09.