CVE-2026-42290: protobuf.js is Vulnerable to OS Command Injection in the CLI
(updated )
pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42290 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →