CVE-2026-1245
Estado: AnalizadaMedia (6.5)—
A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-1245",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-1245",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-21T16:44:44.620209Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "binary-parser",
"product": "binary-parser",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.3.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2026-01-20T19:15:50.573",
"references": [
{
"url": "https://github.com/keichi/binary-parser",
"tags": [
"Product"
],
"source": "cret@cert.org"
},
{
"url": "https://github.com/keichi/binary-parser/pull/283",
"tags": [
"Patch"
],
"source": "cret@cert.org"
},
{
"url": "https://kb.cert.org/vuls/id/102648",
"tags": [
"Third Party Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://www.npmjs.com/package/binary-parser",
"tags": [
"Product"
],
"source": "cret@cert.org"
},
{
"url": "https://www.kb.cert.org/vuls/id/102648",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated code without sanitization, enabling attackers to execute arbitrary code in the context of the Node.js process."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyección de código en la librería binary-parser anterior a la versión 2.3.0 permite la ejecución arbitraria de código JavaScript cuando se utilizan valores no confiables en nombres de campos del analizador o parámetros de codificación. La librería interpola directamente estos valores en código generado dinámicamente sin sanitización, permitiendo a los atacantes ejecutar código arbitrario en el contexto del proceso de Node.js."
}
],
"lastModified": "2026-06-17T10:15:23.183",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:keichi:binary-parser:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7FCCACB7-F3FF-4E03-91E5-3D0E0D2F69A2",
"versionEndExcluding": "2.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}