CVE-2026-25521 is a high-severity prototype pollution vulnerability affecting Locutus versions 2.0.12 through 2.0.38, a library that integrates other programming language standard libraries into JavaScript. An attacker can exploit this flaw by crafting malicious input through String.prototype, despite previous attempts to mitigate such issues. This vulnerability carries a CVSS score of 8.8, indicating a high potential for impact including confidentiality, integrity, and availability compromise, with low attack complexity and local privileges required. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.12, < 2.0.39CPE matchmatch criteria | cpe:2.3:a:locutus:locutus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.