CVE-2023-36665: Critical severity Protobufjs Project Protobufjs Node.js vulnerability

Published Jul 5, 2023
·
Updated

"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.

Other sources

protobuf.js (aka protobufjs) 6.10.0 until 6.11.4 and 7.0.0 until 7.2.4 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty. NOTE: this CVE Record is about Object.constructor.prototype.<new-property> = ...; whereas CVE-2022-25878 was about Object.proto.<new-property> = ...; instead.

Affected Software

4 affected componentsFixes available
npm/protobufjs>=7.0.0<7.2.5
7.2.5
npm/protobufjs>=6.10.0<6.11.4
6.11.4
Protobufjs Project Protobufjs Node.js>=6.10.0<7.2.5
Protobufjs Project Protobufjs Node.js>=6.10.0<7.2.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/protobufjs to a version that resolves this vulnerability.

    Fixed in 7.2.5
  2. Upgrade

    Upgrade npm/protobufjs to a version that resolves this vulnerability.

    Fixed in 6.11.4

Event History

Jul 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-36665?

CVE-2023-36665 has a severity rating that indicates a potential risk of prototype pollution.

2

How do I fix CVE-2023-36665?

To mitigate CVE-2023-36665, upgrade to protobuf.js version 7.2.5 or 6.11.4.

3

What systems are affected by CVE-2023-36665?

CVE-2023-36665 affects protobuf.js versions from 6.10.0 to 7.x before 7.2.5.

4

What type of vulnerability is CVE-2023-36665?

CVE-2023-36665 is classified as a prototype pollution vulnerability.

5

Can CVE-2023-36665 be exploited remotely?

Yes, an attacker could potentially exploit CVE-2023-36665 remotely if they can send a user-controlled protobuf message.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203