Sploitus

CVE-2026-41242

1 known exploit for CVE-2026-41242

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

Affected products
Protobufjs
Protobufjs Project Protobufjs
< 7.5.5, 8.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.7% (52th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2026-04-18
CVE-2026-41242 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-41242

Proof-of-concept code and exploit modules indexed by Sploitus