CVE Tools
Back to feed
Research protobuf.js rce protobufjs-cli protobuf.js project web-app

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.