LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-54271

protobufjs project · protobufjs-cli

Published
CVSS8.2
Severityhigh
WeaknessCWE-94
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

Description

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON descriptor input. The common case of parsing schemas from .proto files is not affected. This is a bypass of CVE-2026-44295. An attacker who can provide or influence pre-parsed JSON descriptors passed to pbjs static code generation may be able to cause generated JavaScript output to contain attacker-controlled code. The injected code may execute if the generated file is later exec

References

← Back to the CVE Tracker

Our coverage of CVE-2026-54271

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-54271.