By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
Computing

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

News Room
Last updated: 2026/01/21 at 2:15 AM
News Room Published 21 January 2026
Share
CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
SHARE

Ravie LakshmananJan 21, 2026Open Source / Vulnerability

A security vulnerability has been disclosed in the popular binary-parser npm library that, if successfully exploited, could result in the execution of arbitrary JavaScript.

The vulnerability, tracked as CVE-2026-1245 (CVSS score: N/A), affects all versions of the module prior to version 2.3.0, which addresses the issue. Patches for the flaw were released on November 26, 2025.

Binary-parser is a widely used parser builder for JavaScript that allows developers to parse binary data. It supports a wide range of common data types, including integers, floating-point values, strings, and arrays. The package attracts approximately 13,000 downloads on a weekly basis.

According to an advisory released by the CERT Coordination Center (CERT/CC), the vulnerability has to do with a lack of sanitization of user-supplied values, such as parser field names and encoding parameters, when the JavaScript parser code is dynamically generated at runtime using the “Function” constructor.

Cybersecurity

It’s worth noting that the npm library builds JavaScript source code as a string that represents the parsing logic and compiles it using the Function constructor and caches it as an executable function to parse buffers efficiently.

However, as a result of CVE-2026-1245, an attacker-controlled input could make its way to the generated code without adequate validation, causing the application to parse untrusted data, resulting in the execution of arbitrary code. Applications that use only static, hard-coded parser definitions are not affected by the flaw.

“In affected applications that construct parser definitions using untrusted input, an attacker may be able to execute arbitrary JavaScript code with the privileges of the Node.js process,” CERT/CC said. “This could allow access to local data, manipulation of application logic, or execution of system commands depending on the deployment environment.”

Security researcher Maor Caplan has been credited with discovering and reporting the vulnerability. Users of binary-parser are advised to upgrade to version 2.3.0 and avoid passing user-controlled values into parser field names or encoding parameters.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article The First Planet Parade of 2026 Is in February: Here's How to See It The First Planet Parade of 2026 Is in February: Here's How to See It
Next Article OnePlus flatly denies shutdown rumors, calls report ‘false’ OnePlus flatly denies shutdown rumors, calls report ‘false’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Shopping trick slashes Ring camera price from £80 to £40 in ‘limited time’ deal
Shopping trick slashes Ring camera price from £80 to £40 in ‘limited time’ deal
News
This could be the ridiculously thin iPhone Air battery pack we’ve been looking for
This could be the ridiculously thin iPhone Air battery pack we’ve been looking for
Gadget
COPA-DATA: The software-defined era awakens
COPA-DATA: The software-defined era awakens
Software
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
Computing

You Might also Like

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
Computing

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code

7 Min Read
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs
Computing

Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs

5 Min Read
Sales of base iPhone 17 in China nearly double during initial launch period · TechNode
Computing

Sales of base iPhone 17 in China nearly double during initial launch period · TechNode

1 Min Read
Wicrypt, the startup teaching people to sell internet like software
Computing

Wicrypt, the startup teaching people to sell internet like software

13 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?