BRIEFING NOTE CVE-2026-41242 is a critical code injection vulnerability in protobufjs, a JavaScript library that compiles protobuf definitions into executable functions. Versions prior to 8.0.1 and 7.5.5 are affected. Attackers can inject arbitrary code within the "type" fields of protobuf definitions, which executes during object decoding, allowing complete system compromise. The vulnerability carries a CVSS score of 9.8 CRITICAL with a network-based attack vector requiring no authentication, user interaction, or special privileges. The attack has low complexity and impacts all security objectives: confidentiality, integrity, and availability. This represents a severe threat with unrestricted attack surface and immediate exploitation potential. The vulnerability is currently listed on the CISA KEV Catalog as actively exploited in the wild. While specific public exploit code availability is not confirmed in the provided data, the presence on the active Hot List and higher-than-average EPSS score (relative to 0.156% of all CVEs) indicate demonstrated exploitation and community attention. Organizations using affected protobufjs versions should prioritize immediate patching to 8.0.1 or 7.5.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.5CPE matchmatch criteria | cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:protobufjs_project:protobufjs:8.0.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.