VYPR
Medium severity4.8OSV Advisory· Published Jul 8, 2026· Updated Jul 13, 2026

CVE-2026-59876

CVE-2026-59876

Description

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own map entry in protobufjs/ext/textformat. This issue is fixed in version 8.6.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
protobufjsnpm
>= 8.2.0, < 8.6.58.6.5

Affected products

4
  • Protobufjs/ProtobufjsOSV3 versions
    protobufjs-v8.6.4, protobufjs-cli-v2.5.5, protobufjs-v8.6.3, …+ 2 more
    • (no CPE)range: protobufjs-v8.6.4, protobufjs-cli-v2.5.5, protobufjs-v8.6.3, …
    • cpe:2.3:a:protobufjs_project:protobufjs:*:*:*:*:*:node.js:*:*range: >=8.2.0,<8.6.5
    • (no CPE)range: <8.6.5
  • osv-coords
    Range: < 0.8.7-r5

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.