[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkgK35wlqCtz94YQCTsdZ7WwfMWTZR0nxZci-XfTq6K8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"dd1b734b-ff29-434c-b33c-32acc12695fb","critical-rce-vulnerability-in-popular-javascript-library-affects-52m-downloads","4402f742-d9af-4273-8d40-1310e13279c3","Critical RCE Vulnerability in Popular JavaScript Library Affects 52M Downloads","A critical remote code execution vulnerability was discovered in protobuf.js, a widely-used JavaScript library with over 52 million downloads, caused by unsafe use of the Function constructor that allows malicious code injection through schema names. This demonstrates how third-party dependencies can introduce severe security risks into applications, as the library dynamically generated code without proper input validation or sanitization. The vulnerability highlights the importance of supply chain security, as a single compromised library can affect countless downstream applications that depend on it. Organizations must implement robust dependency management practices to detect and respond to such vulnerabilities in their software supply chain.","**Immediate actions:**\n- Update protobuf.js to the patched version immediately across all applications\n- Scan all applications and systems for vulnerable versions of protobuf.js\n- Implement emergency change procedures to expedite critical security patches\n\n**Supply chain security:**\n- Deploy automated dependency scanning tools to monitor third-party libraries for vulnerabilities\n- Maintain an accurate inventory of all third-party components and their versions\n- Establish vendor risk assessment processes for critical dependencies\n\n**Long-term improvements:**\n- Implement software composition analysis (SCA) in the CI\u002FCD pipeline\n- Create policies requiring security review of new dependencies before adoption\n- Establish incident response procedures specifically for supply chain vulnerabilities",[12,13,14,15,16,17],"CIS Control 2","CIS Control 7","NIST SP 800-161","NIST SSDF","OWASP SCVS","ISO 27001 A.14.2.1","published","2026-04-20T12:09:37.778483+00:00","2026-04-20T12:09:37.658+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fhackread.com\u002F52m-download-protobuf-js-library-rce-schema-handle\u002F","52m-download-protobuf-js-library-hit-by-rce-in-schema-handling-69dccd","52M-Download protobuf.js Library Hit by RCE in Schema Handling",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"a784f4f5-761f-4473-8c69-674dd0848e45","2026-04-20","afternoon","ThreatNoir Afternoon Brief — April 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-20\u002Fthreatnoir-afternoon-brief-2026-04-20.mp3"]