CVE-2026-32304General(locutus / locutus)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch locutus locutus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • locutus

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
locutus

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 203-1203-13
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure1General1
2026-03-132
General1Patch1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-32304 - Critical Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to ... https://www.thehackerwire.com/vulnerability/CVE-2026-32304/ https://t.co/KzHAfOa0Uf

    Post summary

    The post highlights a critical flaw in Locutus’s create_function implementation that could allow code injection, but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000040
    135 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32304: CRITICAL] Beware of security vulnerabilities in Locutus JavaScript library versions prior to 3.0.14. Exploiting create_function() could lead to arbitrary code execution. Update to the latest...#cve,CVE-2026-32304,#cybersecurity https://cvefind.com/CVE-2026-32304

    Post summary

    The tweet alerts that CVE-2026-32304 in Locutus JS before v3.0.14 enables arbitrary code execution via create_function, and advises users to update to the latest version.

    0000049
    602 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32304 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both pa… https://www.cve.org/CVERecord?id=CVE-2026-32304

    Post summary

    The text references CVE-2026‑32304 and a potential issue with the create_function in Locutus versions prior to 3.0.14, but it provides no further technical, exploit, or mitigation details.

    0000087
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32304: Locutus: RCE via unsanitized inp... Direct Function() constructor abuse in Locutus create_function() - zero validation on user input means trivial RCE for ... https://zerodaysignal.com/vulnerability/CVE-2026-32304 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑32304, highlighting an RCE via unsanitized input and Function() constructor abuse, but does not provide PoC, exploit code, or patch details.

    0000056
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applocutuslocutus-node.js-

Explore more