protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments. This vulnerability is fixed in 1.2.1 and 2.0.2.
Metrics
Affected Vendors & Products
References
History
Tue, 19 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Protobufjs Project
Protobufjs Project protobufjs-cli |
|
| CPEs | cpe:2.3:a:protobufjs_project:protobufjs-cli:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Protobufjs Project
Protobufjs Project protobufjs-cli |
Mon, 18 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Protobuf
Protobuf protobuf |
|
| Vendors & Products |
Protobuf
Protobuf protobuf |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments. This vulnerability is fixed in 1.2.1 and 2.0.2. | |
| Title | protobufjs-cli: OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-18T13:54:57.889Z
Reserved: 2026-04-26T12:13:55.551Z
Link: CVE-2026-42290
Updated: 2026-05-18T13:53:13.353Z
Status : Analyzed
Published: 2026-05-13T16:16:47.160
Modified: 2026-05-19T20:56:15.433
Link: CVE-2026-42290
No data.
OpenCVE Enrichment
Updated: 2026-05-14T14:30:15Z