Locutus

Locutus

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 27.03.2026 22:15:47
  • Zuletzt bearbeitet 01.04.2026 14:16:51

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. A...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 27.03.2026 22:14:03
  • Zuletzt bearbeitet 01.04.2026 13:22:49

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation witho...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 12.03.2026 21:24:51
  • Zuletzt bearbeitet 19.03.2026 13:48:33

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arb...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 06.03.2026 17:48:10
  • Zuletzt bearbeitet 13.03.2026 19:07:16

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array function impl...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 04.02.2026 21:20:32
  • Zuletzt bearbeitet 20.02.2026 21:20:40

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 08.06.2021 08:15:06
  • Zuletzt bearbeitet 21.11.2024 05:51:38

The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.

Exploit
  • EPSS 1.72%
  • Veröffentlicht 01.09.2020 10:15:10
  • Zuletzt bearbeitet 21.11.2024 05:37:40

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.