Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.1epss 0.8%
probabilidade de exploração
0.8%top 46% das CVEs
exploração observada
nãonenhuma fonte reporta
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array function implementation. The vulnerability allows an attacker to inject arbitrary JavaScript code into the application's runtime environment. This issue stems from an insecure implementation of the call_user_func_array function (and its wrapper call_user_func), which fails to properly validate all components of a callback array before passing them to eval(). This issue has been patched in version 3.0.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
locutusjs · locutusReferências
https://access.redhat.com/security/cve/CVE-2026-29091https://bugzilla.redhat.com/show_bug.cgi?id=2445262https://github.com/locutusjs/locutus/commit/977a1fb169441e35996a1d2465b512322de500adhttps://github.com/locutusjs/locutus/security/advisories/GHSA-fp25-p6mj-qqg6https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29091.json