GHSA-pr59-h9ph-3fr8
HIGHCVE-2026-54271A previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON descriptor input. The common case of parsing schemas from .proto files is not affected.
- Affected
- >=0, <1.3.2, <= 1.3.1
- Fixed in
- 1.3.2
- Weakness
- CWE-94
- Published
- 2026-06-15
- Source
- osv