CVE-2026-33994
- EPSS 0.1%
- Veröffentlicht 27.03.2026 22:15:47
- Zuletzt bearbeitet 01.04.2026 14:16:51
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. A...
CVE-2026-33993
- EPSS 0.09%
- Veröffentlicht 27.03.2026 22:14:03
- Zuletzt bearbeitet 01.04.2026 13:22:49
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation witho...
CVE-2026-32304
- EPSS 0.1%
- Veröffentlicht 12.03.2026 21:24:51
- Zuletzt bearbeitet 19.03.2026 13:48:33
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arb...
CVE-2026-29091
- EPSS 0.36%
- Veröffentlicht 06.03.2026 17:48:10
- Zuletzt bearbeitet 13.03.2026 19:07:16
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array function impl...
CVE-2026-25521
- EPSS 0.01%
- Veröffentlicht 04.02.2026 21:20:32
- Zuletzt bearbeitet 20.02.2026 21:20:40
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype...
CVE-2021-23392
- EPSS 0.41%
- Veröffentlicht 08.06.2021 08:15:06
- Zuletzt bearbeitet 21.11.2024 05:51:38
The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.
CVE-2020-7719
- EPSS 1.72%
- Veröffentlicht 01.09.2020 10:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:40
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.