CVE Database
/

CVE-2026-1245

Back to search

CVE-2026-1245

Published: Jan 20, 2026

Modified: Jan 21, 2026

PUBLISHED

Description

A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.

VendorProductVersions

binary-parser

binary-parser

affected
0 - < 2.3.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now