CVE-2026-25521Disclosure(locutus / locutus)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch locutus locutus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • locutus

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
locutus

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-04: 3Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 302-04
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25521 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-25521

    Post summary

    The text reports a prototype pollution vulnerability in Locutus versions 2.0.12–2.0.38, providing basic technical details but no PoC, exploit, or mitigation information.

    00010153
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25521: Locutus is vulnerable to Prototy... Locutus's incomplete validation allows String.prototype bypass for object pollution, enabling property injection despit... https://zerodaysignal.com/vulnerability/CVE-2026-25521 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a Locutus prototype‑pollution flaw (CVE‑2026‑25521) that permits property injection via String.prototype bypass, without detailing a PoC, exploit, or patch.

    0000061
    132 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Locutus is vulnerable to Prototype Pollution (CVE-2026-25521). Malicious property injection can lead to further compromise. Upgrade to 2.0.39. #locutus #PrototypePollution #infosec https://www.pulsepatch.io/posts/cve-2026-25521-locutus-prototype-pollution

    Post summary

    Locutus is vulnerable to prototype pollution (CVE‑2026‑25521), allowing malicious property injection that can lead to further compromise; users are advised to upgrade to version 2.0.39.

    0000042
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applocutuslocutus-node.js-

Explore more