← volver
CVE-2026-25521

Locutus is vulnerable to Prototype Pollution

CVSS 9.4 CRITICALEPSS 0.2%CWE-1321
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.4EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 feb 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Productos afectados
locutusjs · locutus

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →