A security vulnerability has been disclosed in the popular npm binary-parser, which, if successfully exploited, could lead to the execution of arbitrary JavaScript code. The vulnerability, tracked as CVE-2026-1245, affects all versions of the module prior to version 2.3.0, which addresses the issue. Fixes for the bug were released on November 26, 2025. binary-parser is a widely used parser builder for JavaScript that allows developers to parse binary data.
See also: Critical vulnerability in Node.js can cause server crashes

It supports a wide range of common data types, including integers, floating-point values, strings, and arrays. The package attracts about 13,000 downloads on a weekly basis. According to an advisory released by the CERT Coordination Center (CERT/CC), the vulnerability is due to a lack of sanitization of user-supplied values, such as parser field names and encoding parameters, when JavaScript parser code is dynamically generated at runtime using the “Function” constructor.
See also: Critical vulnerability in jsPDF allows arbitrary file reading on Node.js installations

The npm library generates JavaScript source code as a string representing the parsing logic and compiles it using the Function constructor, storing it as an executable function for efficient parsing of buffers. However, as a result of CVE-2026-1245, an attacker-controlled input could reach the generated code without sufficient validation, causing the application to parse untrusted data, which could lead to arbitrary code execution.
Applications that use only static, predefined parser definitions are not affected by the bug. “In affected applications that construct parser definitions using untrusted input, an attacker may be able to execute arbitrary JavaScript code with the privileges of the Node.js process,” CERT/CC said.
See also: North Korean hackers exploit React2Shell to deploy EtherRAT

“This could allow access to local data, modification of application logic, or execution of system commands depending on the development environment.” Security researcher Maor Caplan has been credited for discovering and reporting the vulnerability. Users of binary-parser are advised to upgrade to version 2.3.0 and avoid passing user-controlled values in parser field names or encoding parameters.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
