OsVault/npm/locutus
npm2 critical

locutus

8 known vulnerabilities · 2 critical · 0 high

CVE-2026-33994

Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521

Published Mar 27, 2026
CVE-2026-33993

Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()

Published Mar 27, 2026
CVE-2020-7719CRITICAL

Prototype Pollution in locutus

Published May 6, 2021
CVE-2026-25521

locutus is vulnerable to Prototype Pollution

Published Feb 2, 2026
CVE-2026-29091

locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection

Published Mar 4, 2026
CVE-2020-13619CRITICAL

OS Command Injection in Locutus

Published Jul 26, 2021
CVE-2021-23392MEDIUM

Uncontrolled Resource Consumption in locutus

Published Jun 10, 2021
CVE-2026-32304

Locutus vulnerable to RCE via unsanitized input in create_function()

Published Mar 13, 2026
Check your entire dependency tree at onceRun dependency scan →