6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.
Basic Information
ID
CVE-2026-1245
Source
certcc
Published
Jan 20, 2026 at 18:50
Modified
Jan 21, 2026 at 17:10
Affected Product
Vendor
binary-parser
Product
binary-parser
Affected Versions
binary-parser binary-parser 0