CVE-2023-36665Disclosure(protobufjs_project / protobufjs)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve: (1) using the function parse to parse protobuf messages on the fly, (2) loading .proto files by using load/loadSync functions, or (3) providing untrusted input to the functions ReflectionObject.setParsedOption and util.setProperty.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • protobufjs

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-12)
  • 3 total mentions across 2 days

Affected systems

Products
protobufjs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 1Mentions · 2026-05-12: 2Technical Details · 2026-04-17: 1Technical Details · 2026-05-12: 204-1705-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-05-122
Disclosure1General1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Nodejs protobufjs, Prototype Pollution, #CVE-2023-36665 (Critical) https://dailycve.com/nodejs-protobufjs-prototype-pollution-cve-2023-36665-critical/

    Post summary

    Tweet highlights newly disclosed prototype‑pollution flaw (CVE-2023-36665) in Nodejs protobufjs, labeling it critical and directing readers to a dailycve article for details.

    00000128
    203 followersView on X
  • DailyCVE@dailycve
    General

    🔴 protobufjs, Prototype Pollution, #CVE-2023-36665 (critical) https://dailycve.com/protobufjs-prototype-pollution-cve-2023-36665-critical-2/

    Post summary

    A brief tweet announcing a prototype pollution vulnerability in protobufjs (CVE-2023-36665) labeled critical, with a link to a DailyCVE article for further details.

    00000120
    203 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 protobufjs, Prototype Pollution, #CVE-2023-36665 (Critical) https://dailycve.com/protobufjs-prototype-pollution-cve-2023-36665-critical/

    Post summary

    The post announces a critical prototype pollution flaw in protobufjs (CVE‑2023‑36665) without detailing any PoC, exploit, or mitigation.

    0000057
    181 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprotobufjs_projectprotobufjs-node.js-

Explore more