CVE 6.5 MEDIUM

CVE-2026-1245_CVE-2026-1245

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.

Basic Information

ID CVE-2026-1245
Source certcc
Published Jan 20, 2026 at 18:50
Modified Jan 21, 2026 at 17:10

Affected Product

Vendor binary-parser
Product binary-parser
Affected Versions binary-parser binary-parser 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.