CVE-2026-1245Disclosure(keichi / binary-parser)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • binary-parser

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
binary-parser

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-29: 1Technical Details · 2026-01-29: 101-29
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Disclosure

    Node.js binary-parser Library の脆弱性 CVE-2026-1245 が FIX:コード・インジェクションの恐れ https://iototsecnews.jp/2026/01/22/node-js-binary-parser-library-flaw-enables-malicious-code-injection/ Node.jsでバイナリ・データを簡単に扱うためのライブラリ binary-parser に、サーバの完全な乗っ取りに至る深刻な脆弱性が見つかりました。この問題の原因は、プログラムが解析ルールを作成する際、外部から入力された文字列をそのまま JavaScript の命令として組み立てて実行してしまう不備にあります。 具体的には、データのフィールド名や文字コードの設定部分に、悪意のプログラムコードを紛れ込ませることができます。ライブラリ内部で new Function() という仕組みを使って動的にコードを生成しているため、攻撃者が送った “OSのコマンドを実行せよ” といった命令が、Node.js の実行権限で動いてしまいます。この脆弱性は CVE-2026-1245 として報告されており、悪用されると機密情報の流出や、サーバの完全な奪取につながる極めて危険ものです。ご利用のチームは、ご注意ください。 #binaryparserLibrary #CVE20261245 #Nodejs #Vulnerability

    Post summary

    The article announces CVE‑2026‑1245 as a severe code injection flaw in the Node.js binary‑parser library, detailing how malicious JavaScript can be executed but does not provide exploit or mitigation information.

    01000130
    485 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkeichibinary-parser-node.js-

Explore more