Security Advisory

CVE-2026-25521

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-04 21:20:32
Last updated 2026-02-05 14:31:43
Assigner GitHub_M
State PUBLISHED

Description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.