{"id":"GHSA-75px-5xx7-5xc7","summary":"protobuf.js: Code generation gadget after prototype pollution","details":"## Summary\n\nprotobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If `Object.prototype` had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information.\n\nThis could cause attacker-controlled strings to be emitted into generated JavaScript code.\n\n## Impact\n\nAn attacker who can first trigger a prototype pollution vulnerability may be able to influence generated protobufjs encode or decode functions in a way that can lead to arbitrary JavaScript execution.\n\nThis issue requires a separate prototype pollution primitive before protobufjs is invoked.\n\nApplications without a reachable prototype pollution primitive are not directly exploitable through this issue alone.\n\n## Preconditions\n\n- The application or one of its dependencies must allow an attacker to pollute `Object.prototype`.\n- The polluted property must affect protobufjs internal type lookup behavior.\n- The application must use protobufjs functionality that generates encode or decode code for affected types.\n- The generated code path must be reached after the prototype pollution has occurred.\n\n## Workarounds\n\nAvoid running affected versions in applications where attacker-controlled input can pollute `Object.prototype`. If immediate upgrade is not possible, remove or mitigate reachable prototype pollution primitives and isolate schema/message processing from untrusted application state.","aliases":["CVE-2026-44291"],"modified":"2026-07-17T21:12:10.299902791Z","published":"2026-05-12T15:01:24Z","database_specific":{"github_reviewed_at":"2026-05-12T15:01:24Z","nvd_published_at":"2026-05-13T16:16:55Z","cwe_ids":["CWE-1321","CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-75px-5xx7-5xc7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44291"},{"type":"PACKAGE","url":"https://github.com/protobufjs/protobuf.js"},{"type":"WEB","url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.6"},{"type":"WEB","url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.2"}],"affected":[{"package":{"name":"protobufjs","ecosystem":"npm","purl":"pkg:npm/protobufjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.5.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.5.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-75px-5xx7-5xc7/GHSA-75px-5xx7-5xc7.json"}},{"package":{"name":"protobufjs","ecosystem":"npm","purl":"pkg:npm/protobufjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.0.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-75px-5xx7-5xc7/GHSA-75px-5xx7-5xc7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}