Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Critical flaw in Protobuf library enables JavaScript code execution
    Cybersecurity

    Critical flaw in Protobuf library enables JavaScript code execution

    adminBy adminApril 18, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Critical flaw in Protobuf library enables JavaScript code execution
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Critical flaw in Protobuf library enables JavaScript code execution

    Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google’s Protocol Buffers.

    The tool is highly popular in the Node Package Manager (npm) registry, with an average of nearly 50 million weekly downloads. It is used for inter-service communication, in real-time applications, and for efficient storage of structured data in databases and cloud environments.

    In a report on Friday, application security company Endor Labs says that the remote code execution vulnerability (RCE) in protobuf.js is caused by unsafe dynamic code generation.

    Wiz

    The security issue has not received an official CVE number and is currently being tracked as GHSA-xq3m-2v4x-88gg, the identifier assigned by GitHub.

    Endor Labs explains that the library builds JavaScript functions from protobuf schemas by concatenating strings and executing them via the Function() constructor, but it fails to validate schema-derived identifiers, such as message names.

    This lets an attacker supply a malicious schema that injects arbitrary code into the generated function, which is then executed when the application processes a message using that schema.

    This opens the path to RCE on servers or applications that load attacker-influenced schemas, granting access to environment variables, credentials, databases, and internal systems, and even allowing lateral movement within the infrastructure.

    The attack could also affect developer machines if those load and decode untrusted schemas locally.

    The flaw impacts protobuf.js versions 8.0.0/7.5.4 and lower. Endor Labs recommends upgrading to 8.0.1 and 7.5.5, which address the issue.

    The patch sanitizes type names by stripping non-alphanumeric characters, preventing the attacker from closing the synthetic function. However, Endor comments that a longer-term fix would be to stop round-tripping attacker-reachable identifiers through Function at all.

    Endor Labs is warning that “exploitation is straightforward,” and that the minimal proof-of-concept (PoC) included in the security advisory reflects this. However, no active exploitation in the wild has been observed to date.

    The vulnerability was reported by Endor Labs researcher and security bug bounty hunter Cristian Staicu on March 2, and the protobuf.js maintainers released a patch on  GitHub on March 11. Fixes to the npm packages were made available on April 4 for the 8.x branch and on April 15 for the 7.x branch.

    Apart from upgrading to patched versions, Endor Labs also recommends that system administrators audit transitive dependencies, treat schema-loading as untrusted input, and prefer precompiled/static schemas in production.


    tines

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Code Critical enables Execution Flaw JavaScript Library Protobuf
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleDive Into The Stanford Report Data
    Next Article Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery
    admin
    • Website

    Related Posts

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

    April 18, 2026

    $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    U.S. search ad revenue reached $114.2 billion in 2025

    April 18, 2026

    You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off

    April 18, 2026

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026

    Critical flaw in Protobuf library enables JavaScript code execution

    April 18, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,385)
    • Privacy & Online Earning (171)
    • SEO & Digital Marketing (848)
    • Tech Tools & Mobile / Apps (1,654)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    U.S. search ad revenue reached $114.2 billion in 2025

    April 18, 2026

    You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off

    April 18, 2026

    Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery

    April 18, 2026
    Most Popular
    • U.S. search ad revenue reached $114.2 billion in 2025
    • You Should Start Spring Cleaning With This Dyson Cordless Vacuum While It’s on Sale for Over $200 Off
    • Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery
    • Critical flaw in Protobuf library enables JavaScript code execution
    • Dive Into The Stanford Report Data
    • Claude Cowork took one repetitive task for me, and I’m very impressed
    • Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
    • ConnectBot v1.10.4 by Kenny Root
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.