CVE-2026-25521
EUVD-2026-534004.02.2026, 22:15
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| locutus | locutus | 2.0.12 ≤ 𝑥 < 2.0.39 |
𝑥
= Vulnerable software versions