Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
protobufjs 7.5.4 is reported with multiple serious issues including denial of service and possible code-injection conditions in generated-code-related paths. Because this skill depends on @google/genai, which directly pulls protobufjs, malformed remote data or untrusted schema/message handling could expose the runtime to crashes or unsafe code paths.
- Content
