Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more
- Category
- Supply Chain
- Confidence
- 96% confidence
- Finding
The skill depends on protobufjs 7.5.4, which is flagged with multiple advisories including denial-of-service from crafted inputs, code generation issues, and potential code injection paths. In a skill that may consume external transit data or protobuf payloads, malformed or attacker-controlled messages could crash the process, trigger unsafe generated-code behavior, or otherwise compromise availability and possibly integrity depending on how codegen features are used.
- Content
