protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output without sufficient sanitization. This vulnerability is fixed in 1.2.1 and 2.0.2.
References
| Link | Resource |
|---|---|
| https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-6r35-46g8-jcw9 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-13 16:16
Updated : 2026-06-17 10:50
NVD link : CVE-2026-44295
Mitre link : CVE-2026-44295
CVE.ORG link : CVE-2026-44295
JSON object : View
Products Affected
protobufjs_project
- protobufjs-cli
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
