Description
protobufjs could execute generated JavaScript code derived from protobuf schema metadata. When loading a crafted JSON descriptor, schema-controlled type names and type references could reach runtime code generation without sufficient validation.
Recommendation
Update the protobufjs package to the latest compatible version. Followings are version details:
Affected version(s): **< 7.5.5 >= 8.0.0, < 8.0.1** Patched version(s): **7.5.5 8.0.1**
References
Related Issues
- Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader - CVE-2026-53597
- Electerm runWidget has a path traversal that leads to arbitrary code execution - CVE-2026-43940
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code - CVE-2023-45133
You might also like:
- Tags:
- npm
- protobufjs
Anything's wrong? Let us know Last updated on May 04, 2026


