CVE-2026-29091 describes a remote code execution (RCE) vulnerability in the Locutus project, a JavaScript library designed to bring standard libraries from other programming languages to JavaScript. Specifically, versions prior to 3.0.0 are affected due to an insecure implementation of the call_user_func_array function, which fails to properly validate callback array components before passing them to eval(). This flaw allows an attacker to inject arbitrary JavaScript code into the application's runtime. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a severe risk. Its attack vector is network-based with high impact on confidentiality, integrity, and availability, but requires high attack complexity. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion is minimal, with only one mention observed, and there is no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.0CPE matchmatch criteria | cpe:2.3:a:locutus:locutus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.