Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-36665: Protobuf.js 6.10.0 to 7.x before 7.2.5 allows malicious data to alter JavaScript code
CVE-2023-36665 · published today
Summary
If an attacker can control the data used to parse or load Protobuf files, they may be able to alter the behavior of JavaScript code by adding or changing functions. This can happen through various ways of using the Protobuf.js library, including parsing messages on the fly or loading files. To stay safe, you should update to Protobuf.js version 7.2.5 or later.
What to do
- Update google-wombot protobufjs to version 6.11.4.
- Update google-wombot protobufjs to version 7.2.5.
- Update rootio @rootio/protobufjs to version 6.11.4-root.io.5.
- Update GitHub Actions protobufjs to version 6.11.4-aikido.5.
- Update rootio @rootio/protobufjs to version 6.11.4-root.io.3.
- Update GitHub Actions protobufjs to version 6.11.4-aikido.3.
- Update rootio @rootio/protobufjs to version 6.11.4-root.io.4.
- Update GitHub Actions protobufjs to version 6.11.4-aikido.4.
- Update protobufjs to version 6.11.4-aikido.5.
- Update protobufjs_project protobufjs to version 7.2.5 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | google-wombot | protobufjs |
>= 6.10.0, < 6.11.4 >= 7.0.0, < 7.2.5 Fix: upgrade to 6.11.4
|
| – | protobufjs_project | protobufjs |
>= 6.10.0, < 7.2.5 cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:* |
| Root:npm | rootio | @rootio/protobufjs |
< 6.11.4-root.io.5 < 6.11.4-root.io.3 < 6.11.4-root.io.4 Fix: upgrade to 6.11.4-root.io.5
|
| Root:npm | GitHub Actions | protobufjs |
< 6.11.4-aikido.5 < 6.11.4-aikido.3 < 6.11.4-aikido.4 Fix: upgrade to 6.11.4-aikido.5
|
| Root:npm | – | protobufjs |
< 6.11.4-aikido.5 Fix: upgrade to 6.11.4-aikido.5
|
Original advisory text
CVE-2023-36665 in protobufjs - Patched by Root
Root has patched CVE-2023-36665 in the protobufjs package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-36665
- https://github.com/protobufjs/protobuf.js/pull/1899
- https://github.com/protobufjs/protobuf.js/commit/e66379f451b0393c27d87b37fa7d271...
- https://github.com/protobufjs/protobuf.js/compare/protobufjs-v7.2.3...protobufjs...
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4
- https://www.code-intelligence.com/blog/cve-protobufjs-prototype-pollution-cve-20...
- https://github.com/protobufjs/protobuf.js/commits/release-6.11.4
- https://github.com/protobufjs/protobuf.js/issues/1918#issuecomment-1723500294
- https://security.netapp.com/advisory/ntap-20240628-0006
- https://github.com/advisories/GHSA-h755-8qp9-cq85
- https://security.netapp.com/advisory/ntap-20240628-0006/
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 2%
Type
CWE-1321Prototype Pollution
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta