---
id: CVE-2026-41242
title: protobufjs compiles protobuf definitions into JavaScript (JS) functions
summary: >-
  protobufjs compiles protobuf definitions into JavaScript (JS) functions. In
  versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the
  "type" fields of protobuf definitions, which will then execute during object
  decodi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: protobufjs_project
product: protobufjs
affected:
  - protobufjs < 7.5.5
  - protobufjs = 8.0.0
patched:
  - protobufjs 7.5.5
published: '2026-04-18'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:19:52.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41242'
references:
  - url: >-
      https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75
    label: security-advisories@github.com
  - url: >-
      https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956
    label: security-advisories@github.com
  - url: 'https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5'
    label: security-advisories@github.com
  - url: 'https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:21338'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26234'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:62260'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-41242'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2459442'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-04-20T16:03:39.054181Z'
scores:
  nvd: 9.8
  cna: 9.4
epss: 0.0099
epssPercentile: 0.61024
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/4chech/CVE-2026-41242'
    - 'https://github.com/Giangdurian/CVE-2026-41242'
  checkedAt: '2026-09-27T10:33:46.216Z'
ingestedAt: '2026-07-10T13:03:45.572Z'
---

## Overview

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.

## Affected

- `protobufjs < 7.5.5`
- `protobufjs = 8.0.0`

## Remediation

Upgrade past the affected range:

- `protobufjs 7.5.5`
