Echo: protobufjs: security update to 7.5.6

high Tenable Cloud Security Plugin ID 462632

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2,
protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated
encode and decode functions. If Object.prototype had already been polluted, those lookup tables could
resolve attacker-controlled inherited properties as valid protobuf type information. This could cause
attacker-controlled strings to be emitted into generated JavaScript code. This vulnerability is fixed in
7.5.6 and 8.0.2. (CVE-2026-44291)

Solution

Update the protobufjs library and its related packages to version 7.5.6 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-44291

Plugin Details

Severity: High

ID: 462632

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-44291

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-44291