CVE-2026-25521: Locutus

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.

Affected products

  • Locutus Locutus: from 2.0.12, before 2.0.39 (fixed in 2.0.39)

Published 2026-02-04. Last modified 2026-07-15.