Research protobuf.js rce protobufjs-cli protobuf.js project web-app
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
CVE Tools coverage
Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.