Back to Blog
critical SEVERITY5 min read

How Arbitrary Code Execution via Protobuf Definition Injection Happens in Node.js and How to Fix It

A critical vulnerability in protobufjs (CVE-2026-41242) allowed attackers to execute arbitrary code by injecting malicious type fields into protobuf definitions. This fix upgrades the protobufjs dependency from version 7.3.0 to 7.6.5, eliminating the attack vector in a private Node.js application's dependency tree.

O
By Orbis AppSec
•Technically reviewed by Anupam Mediratta•Published August 25, 2026•Reviewed August 25, 2026

Answer Summary

CVE-2026-41242 is a critical arbitrary code execution vulnerability in protobufjs, a Protocol Buffers library for JavaScript/Node.js. The flaw allows attackers to inject malicious type fields into protobuf definitions, leading to code execution during message parsing. The fix involves upgrading protobufjs to version 7.6.5 or later, which properly validates and sanitizes type field definitions before processing.

Vulnerability at a Glance

cweCWE-94 (Improper Control of Generation of Code)
fixUpgrade protobufjs to version 7.6.5 which sanitizes type fields
riskRemote code execution through crafted protobuf definitions
languageJavaScript/Node.js
root causeInsufficient validation of protobuf type field definitions before code generation
vulnerabilityArbitrary Code Execution via Protobuf Definition Injection

Introduction

In a private Node.js application's bun.lock file, Trivy detected a critical vulnerability lurking in the dependency tree: CVE-2026-41242 in protobufjs version 7.3.0. This wasn't just a theoretical risk—the vulnerability allowed arbitrary code execution through carefully crafted protobuf definition type fields, potentially giving attackers complete control over the application runtime.

The bun.lock file pinned several protobufjs sub-packages at vulnerable versions, including @protobufjs/codegen@2.0.4, @protobufjs/eventemitter@1.1.0, and @protobufjs/fetch@1.1.0. These components work together to parse and generate code from Protocol Buffer definitions, and a flaw in how type fields were processed created a dangerous injection point.

For developers working with Protocol Buffers in Node.js applications, this vulnerability highlights a critical truth: even widely-used serialization libraries can harbor severe security flaws that require immediate attention.

The Vulnerability Explained

Protocol Buffers (protobuf) is Google's language-neutral data serialization format, and protobufjs is the most popular JavaScript implementation. The library includes a code generation feature (@protobufjs/codegen) that dynamically creates JavaScript functions from protobuf definitions.

CVE-2026-41242 exploits a flaw in how protobufjs handles type field definitions. When processing a .proto file or a JSON-based protobuf definition, the library's codegen component would incorporate type field values directly into generated code without proper sanitization.

Here's what made the vulnerable version dangerous:

// In @protobufjs/codegen@2.0.4, type fields could be injected
// The library would generate code like:
function encode(message) {
    // User-controlled type field value inserted here
    writer.uint32(/* field tag */).${typeField}(message.value);
}

An attacker could craft a malicious protobuf definition with a type field containing JavaScript code:

{
  "nested": {
    "MaliciousMessage": {
      "fields": {
        "payload": {
          "type": "string'); require('child_process').exec('malicious-command'); //",
          "id": 1
        }
      }
    }
  }
}

When protobufjs processed this definition, the injected code would be incorporated into the generated encoder/decoder functions and executed when those functions were called.

Real-World Attack Scenario

Consider this application's context: a Node.js server that might accept protobuf definitions from configuration files, external services, or even user uploads. An attacker who could influence the protobuf schema—even through a seemingly innocuous configuration change—could achieve:

  1. Remote Code Execution: Running arbitrary system commands on the server
  2. Data Exfiltration: Accessing environment variables, database credentials, or sensitive files
  3. Lateral Movement: Using the compromised server to attack other internal systems

The severity is compounded because the code execution happens during the parsing/compilation phase, before any application-level input validation could intervene.

The Fix

The fix involved explicitly pinning protobufjs to version 7.6.5 in the bun.lock file, which pulls in patched versions of all sub-packages:

Before (Vulnerable)

"@protobufjs/codegen": ["@protobufjs/codegen@2.0.4", "", {}, "sha512-YyFaikqM5sH0ziFZCN3xDC7zeGaB/d0IUb9CATugHWbd1FRFwWwt4ld4OYMPWu5a3Xe01mGAULCdqhMlPl29Jg=="],

"@protobufjs/eventemitter": ["@protobufjs/eventemitter@1.1.0", "", {}, "sha512-j9ednRT81vYJ9OfVuXG6ERSTdEL1xVsNgqpkxMsbIabzSo3goCjDIveeGv5d03om39ML71RdmrGNjG5SReBP/Q=="],

"@protobufjs/fetch": ["@protobufjs/fetch@1.1.0", "", { "dependencies": { "@protobufjs/aspromise": "1.1.2", "@protobufjs/inquire": "1.1.0" } }, "sha512-lljVXpqXebpsijW71PZaCYeIcE5on1w5DlQy5WH6GLbFryLUrBD4932W/E2BSpfRJWseIL4v/KPgBFxDOIdKpQ=="],

"@protobufjs/inquire": ["@protobufjs/inquire@1.1.0", "", {}, "sha512-kdSefcPdruJiFMVSbn801t4vFK7KB/5gd2fYvrxhuJYg8ILrmn9SKSX2tZdV6V+ksulWqS7aXjBcRXl3wHoD9Q=="],

After (Patched)

"protobufjs": "7.6.5",

"@protobufjs/codegen": ["@protobufjs/codegen@2.0.5", "", {}, "sha512-zgXFLzW3Ap33e6d0Wlj4MGIm6Ce8O89n/apUaGNB/jx+hw+ruWEp7EwGUshdLKVRCxZW12fp9r40E1mQrf/34g=="],

"@protobufjs/eventemitter": ["@protobufjs/eventemitter@1.1.1", "", {}, "sha512-vW1GmwMZNnL+gMRaovlh9yZX74kc+TTU3FObkkurpMaRtBfLP3ldjS9KQWlwZgraRE0+dheEEoAxdzcJQ8eXZg=="],

"@protobufjs/fetch": ["@protobufjs/fetch@1.1.1", "", { "dependencies": { "@protobufjs/aspromise": "^1.1.1" } }, "sha512-GpptLrs57adMSuHi3VNj0mAF8dwh36LMaYF6XyJ6JMWlVsc+t42tm1HSEDmOs3A8fC9yyeisgLhsTVQokOZ0zw=="],

The key changes include:

  1. Explicit protobufjs pin: Adding "protobufjs": "7.6.5" to the overrides section ensures the patched version is used throughout the dependency tree
  2. Updated codegen: @protobufjs/codegen upgraded from 2.0.4 to 2.0.5, which includes sanitization of type field values
  3. Updated sub-packages: All related packages (eventemitter, fetch) updated to versions that work correctly with the security fixes
  4. Removed vulnerable inquire: The @protobufjs/inquire@1.1.0 dependency was removed from the explicit resolution

The patched version (7.6.5) implements proper escaping and validation of type field definitions, ensuring that malicious strings cannot break out of the intended code context during generation.

Key Takeaways

  • Protobufjs versions before 7.6.5 are vulnerable to CVE-2026-41242—audit your bun.lock, package-lock.json, or yarn.lock for affected versions
  • The @protobufjs/codegen package is the specific attack surface—version 2.0.4 and earlier lack proper type field sanitization
  • Transitive dependencies can introduce critical vulnerabilities—even if you don't directly import protobufjs, it may exist in your dependency tree
  • Lockfile overrides are essential for security patches—adding explicit version pins ensures vulnerable transitive dependencies are replaced
  • Code generation libraries require extra scrutiny—any library that generates executable code from external input is a high-risk component

How Orbis AppSec Detected This

  • Source: Protobuf definition files or JSON schemas containing type field definitions
  • Sink: @protobufjs/codegen@2.0.4 code generation functions that incorporate type fields into generated JavaScript
  • Missing control: Input sanitization and escaping of type field values before code generation
  • CWE: CWE-94 (Improper Control of Generation of Code)
  • Fix: Upgraded protobufjs to version 7.6.5 which properly sanitizes type field definitions before incorporating them into generated code

Orbis AppSec automatically detected this vulnerability and opened a pull request with the fix. Try Orbis AppSec on your repositories to find and fix issues like this automatically.

Conclusion

CVE-2026-41242 demonstrates how code generation libraries can become unexpected attack vectors. The protobufjs vulnerability allowed arbitrary code execution through a seemingly innocuous feature—type field definitions in protobuf schemas. By upgrading to version 7.6.5, the application eliminated this critical risk.

For Node.js developers, this serves as a reminder that dependency security extends beyond your direct imports. Regular vulnerability scanning, explicit version pinning, and automated security tooling are essential practices for maintaining a secure application. The fix in this case was straightforward—a version bump—but detecting the vulnerability required the kind of automated analysis that catches issues before they become incidents.

Prevention and further reading

View the Security Fix

Check out the pull request that fixed this vulnerability

View PR #10807

Related Articles

high

CVE-2026-4800: lodash Template Imports Allow Code Execution

CVE-2026-4800 affects lodash's `_.template()` templating API, where untrusted input reaching the `imports` option can lead to arbitrary code execution. The fix was shipped as a dependency upgrade from lodash 4.17.21 to 4.18.1 in the project's lockfile, though the PR itself notes it was never verified against the actual code paths in this repository.

critical

proxy-addr 2.0.7 IP Spoofing: CVE-2026-90711 Trust Bypass

A critical vulnerability in proxy-addr 2.0.7 allowed attackers to spoof client IP addresses by manipulating X-Forwarded-For headers when the trust chain evaluation contained specific misconfigurations. The fix in version 2.0.8 hardens the trust evaluation logic to prevent IP address falsification in Express.js applications relying on this common middleware dependency.

high

TweenMax `_applyCycle` Prototype Pollution via vars.cycle Keys

A bundled copy of the TweenMax animation library copied attacker-influenceable `vars.cycle` property names straight onto a tween configuration object using an unguarded `for...in` loop, so a key named `__proto__`, `constructor`, or `prototype` was written through to the object's prototype chain. The fix adds an explicit key denylist to both copies of the `_applyCycle` helper so those three names are skipped during the merge. No CVE or GHSA is assigned; the issue is tracked as CWE-1321 (Improperl

high

picomatch 2.3.1 ReDoS: Extglob Pattern Catastrophic Backtracking

picomatch versions below 2.3.2, 3.0.2, or 4.0.4 contain a Regular Expression Denial of Service vulnerability in extglob pattern parsing. An attacker can cause catastrophic backtracking with patterns containing nested alternations and quantifiers, freezing any Node.js process that evaluates untrusted glob expressions.

critical

pet-window.js Dynamic Code Evaluation: CWE-94 Hardening via Number

The pet-window module constructed dynamic JavaScript by embedding raw configuration values into code strings. An attacker with local access could inject arbitrary JavaScript by modifying stored configuration. The fix replaces string interpolation with explicit Number() coercion and NaN validation for all numeric configuration parameters.

high

sanitizeUnicodeInput(): Fullwidth U+ Bypasses Codepoint Validation

The `sanitizeUnicodeInput()` helper used by the project character-range settings screen rewrote `U+` prefixes to `0x` and called `parseInt()`, but never normalized its argument first. Compatibility-equivalent forms such as fullwidth `U+`, superscript digits, or mathematical alphanumerics never matched the `/U\+/gi` regex, fell through to the `else return inputString` branch, and were handed back to callers verbatim as "sanitized" values. The fix inserts a `String.prototype.normalize('NFKC')` pas