SB2026041628 - Code Injection in protobuf.js



SB2026041628 - Code Injection in protobuf.js

Published: April 16, 2026

Security Bulletin ID SB2026041628
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: N/A)

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to code injection in protobuf definition compilation when processing attacker-controlled protobuf definitions during object decoding. A remote user can inject arbitrary code into the "type" fields of protobuf definitions to execute arbitrary code.

Exploitation requires control over the protobuf definition files used by the application.


Remediation

Install update from vendor's website.