CVE-2026-25521

critical Red Hat
CVSS v3 Base Score
9.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published: February 4, 2026
Last Modified: February 4, 2026
Vendor: Red Hat

Description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using String.prototype. This issue has been patched in version 2.0.39.

CWE

CWE-915

Affected Products

Logging Subsystem for Red Hat OpenShift

References