protobuf.js
-
Six protobuf.js flaws can expose Node.js apps to code execution, denial of service
Six vulnerabilities in protobuf.js could enable remote code execution or denial of service in Node.js apps, according to a Cyera technical analysis. Patches are available for affected protobufjs and protobufjs-cli releases.
-
Critical protobuf.js flaw enables JavaScript code execution
A critical flaw in protobuf.js can let attackers execute JavaScript code through malicious schemas, with a proof-of-concept now public. The issue affects versions 8.0.0 and 7.5.4 and earlier, and patched releases are available.


