Protocol Buffers for JavaScript (& TypeScript).
72%
Total Score
10
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41242 New protobufjs is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 8.0.0 - 8.0.1 and 0.0.0 - 7.5.5. | 0.0.0 - 7.5.58.0.0 - 8.0.1 | Critical |
AIKIDO-2026-10467 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. protobufjs is vulnerable to Prototype Pollution in versions 0.0.1 - 8.0.0. | 0.0.1 - 8.0.0 | Medium |
CVE-2023-36665 protobufjs is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.10.0 - 6.11.4 and 7.0.0 - 7.2.5. | 6.10.0 - 6.11.47.0.0 - 7.2.5 | Critical |
CVE-2022-25878 protobufjs is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 6.11.0 - 6.11.3 and 6.10.0 - 6.10.3. | 6.10.0 - 6.10.36.11.0 - 6.11.3 | High |
CVE-2018-3738 protobufjs is vulnerable to Inefficient Regular Expression Complexity in versions 6.0.0 - 6.8.6 and 0.0.0 - 5.0.3. | 0.0.0 - 5.0.36.0.0 - 6.8.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
long Version ^5.0.0 | — | — |
@types/node Version >=13.7.0 | — | — |
@protobufjs/path Version ^1.1.2 | — | — |
@protobufjs/pool Version ^1.1.0 | — | — |
@protobufjs/utf8 Version ^1.1.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant