CVE-2026-1245 describes a code injection vulnerability in the keichi binary-parser library, specifically in versions prior to 2.3.0. This flaw allows arbitrary JavaScript code execution if untrusted input is used in parser field names or encoding parameters, as the library directly interpolates these values without sanitization. With a CVSS score of 6.5 (Medium), this vulnerability has a network attack vector and low attack complexity, potentially leading to limited confidentiality and integrity impacts. The FAUCET Risk Score of 94/100 indicates significant risk. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, the vulnerability has garnered notable community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:keichi:binary-parser:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.