CVE-2026-3951Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry.js of the component Error Response Handler. The manipulation of the argument ID results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-27)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-11: 2Mentions · 2026-05-27: 3PoC Mentioned / Linked · 2026-05-27: 1Technical Details · 2026-03-11: 1Technical Details · 2026-05-27: 303-1105-27
Signal classification1 categories
Disclosure
5100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-112
Disclosure2
2026-05-273
Disclosure3
Full discourse5 posts
  • Geng Yang@geng_zast
    Disclosure

    ZAST identified and verified CVE-2026-3951 in Locker. A user-controlled route parameter was reflected into an HTTP error response without sanitization. That is a real reflected XSS path. https://t.co/jA1484Vc0j

    Post summary

    ZAST identified CVE-2026-3951 as a reflected XSS vulnerability in Locker, where a user-controlled route parameter is reflected into an HTTP error response without sanitization.

    10010156
    49 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: ZAST identified and verified CVE-2026-3951 in Locker (0.0.0, 0.0.1, 0.1.0). A user-controlled route parameter was reflected into an error response without sanitization. That created a reflected XSS path. https://t.co/YXXr8ydi5Y

    Post summary

    ZAST has identified CVE-2026-3951 in Locker, revealing a reflected XSS flaw due to unsanitized route parameters in error responses.

    10000141
    37 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: ZAST identified and verified CVE-2026-3951 in Locker (0.0.0, 0.0.1, 0.1.0). A user-controlled route parameter was reflected into an error response without sanitization. That created a reflected XSS path. https://t.co/eT7JRC4ex3

    Post summary

    ZAST confirms CVE‑2026‑3951 as a reflected XSS flaw in Locker (0.0.0, 0.0.1, 0.1.0) caused by unsanitized route parameters in error responses.

    0000070
    37 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3951 A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry… https://www.cve.org/CVERecord?id=CVE-2026-3951 ----- Traducción: CVE-2026-3951 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3951 as a flaw in LockerProject Locker's authIsAwesome function, without offering further technical details or mitigation guidance.

    0000029
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3951 A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry… https://www.cve.org/CVERecord?id=CVE-2026-3951

    Post summary

    The text announces CVE‑2026‑3951, a flaw in LockerProject Locker’s authIsAwesome function, but provides no details on exploits, patches, or PoCs.

    00000188
    56.6K followersView on X

Explore more