PT-2026-6310 · Locutus · Locutus
Cristianstaicu
+3
·
Published
2026-02-02
·
Updated
2026-02-04
·
CVE-2026-25521
CVSS v4.0
9.4
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Locutus versions 2.0.12 through 2.0.38
Description
Locutus, designed to bring standard libraries from other programming languages to JavaScript for educational purposes, contains a prototype pollution issue. A previous attempt to address prototype pollution by checking for forbidden keys in user input was insufficient. It remains possible to pollute
Object.prototype through a crafted input utilizing String.prototype. This allows for malicious property injection, potentially leading to further compromise.Recommendations
Upgrade to version 2.0.39.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Locutus