HomeSecurityBinary-parser bug allows code execution in Node.js

Binary-parser bug allows code execution in Node.js

A security vulnerability has been disclosed in the popular npm binary-parser, which, if successfully exploited, could lead to the execution of arbitrary JavaScript code. The vulnerability, tracked as CVE-2026-1245, affects all versions of the module prior to version 2.3.0, which addresses the issue. Fixes for the bug were released on November 26, 2025. binary-parser is a widely used parser builder for JavaScript that allows developers to parse binary data.

See also: Critical vulnerability in Node.js can cause server crashes

binary-parser
Binary-parser bug allows code execution in Node.js

It supports a wide range of common data types, including integers, floating-point values, strings, and arrays. The package attracts about 13,000 downloads on a weekly basis. According to an advisory released by the CERT Coordination Center (CERT/CC), the vulnerability is due to a lack of sanitization of user-supplied values, such as parser field names and encoding parameters, when JavaScript parser code is dynamically generated at runtime using the “Function” constructor.

See also: Critical vulnerability in jsPDF allows arbitrary file reading on Node.js installations

Binary-parser bug allows code execution in Node.js
Binary-parser bug allows code execution in Node.js

The npm library generates JavaScript source code as a string representing the parsing logic and compiles it using the Function constructor, storing it as an executable function for efficient parsing of buffers. However, as a result of CVE-2026-1245, an attacker-controlled input could reach the generated code without sufficient validation, causing the application to parse untrusted data, which could lead to arbitrary code execution.

Applications that use only static, predefined parser definitions are not affected by the bug. “In affected applications that construct parser definitions using untrusted input, an attacker may be able to execute arbitrary JavaScript code with the privileges of the Node.js process,” CERT/CC said.

See also: North Korean hackers exploit React2Shell to deploy EtherRAT

Binary-parser bug allows code execution in Node.js

“This could allow access to local data, modification of application logic, or execution of system commands depending on the development environment.” Security researcher Maor Caplan has been credited for discovering and reporting the vulnerability. Users of binary-parser are advised to upgrade to version 2.3.0 and avoid passing user-controlled values ​​in parser field names or encoding parameters.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS