SB2026051263 - OS Command Injection in protobufjs-cli
Published: May 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) OS Command Injection (CVE-ID: CVE-2026-42290)
The vulnerability allows a remote attacker to execute arbitrary shell commands.
The vulnerability exists due to command injection in the pbts CLI tool when processing attacker-influenced input file paths. A remote attacker can supply a crafted file path containing shell metacharacters to execute arbitrary shell commands.
User interaction is required because an application or user must invoke pbts on attacker-influenced paths.
Remediation
Install update from vendor's website.