<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #protobuf</title><description>Articles tagged protobuf on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>protobuf.js RCE: a 52M/week npm package was one bad type name from code execution</title><link>https://devtake.dev/article/protobuf-javascript-rce-cve/</link><guid isPermaLink="true">https://devtake.dev/article/protobuf-javascript-rce-cve/</guid><description>GHSA-xq3m-2v4x-88gg hits protobuf.js ≤8.0.0 / ≤7.5.4. Attacker-controlled schemas executed arbitrary JS on decode. One-line fix patched it.</description><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><category>security</category><category>npm</category><category>protobuf</category><category>javascript</category><category>supply-chain</category><category>rce</category><category>endor-labs</category><category>grpc</category><author>luca-reinhardt</author></item></channel></rss>