CVE-2026-41242: Protobufjs Project Protobufjs
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.
Affected products
- Protobufjs Project Protobufjs: before 7.5.5 (fixed in 7.5.5); version 8.0.0 only
Published 2026-04-18. Last modified 2026-09-09.