Vulnerabilities/

protobuf.js is Vulnerable to OS Command Injection in the CLI

Severity:
High

Description

pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments.

Recommendation

Update the protobufjs-cli package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
protobufjs-cli
Anything's wrong? Let us know Last updated on May 14, 2026