A flaw in the binary-parser npm package before version 2.3.0 lets attackers execute arbitrary JavaScript via unsanitized parser input.
Remote code execution vulnerability CVE-2026-20045 is considered critical by the vendor, as the US cyber agency adds the vulnerability to its KEV catalogue.
To prevent agents from obeying malicious instructions hidden in external data, all text entering an agent's context must be ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results