CVE-2026-32304
Critical · CVSS 9.8Locutus (locutusjs) — Arbitrary Code Execution via unsanitized Function constructor injection (CWE-94, CWE-88)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-94, CWE-88
Description
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.
Search profile — drives PoC discovery
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/locutusjs/locutus/releases/tag/v3.0.14
- https://github.com/locutusjs/locutus/security/advisories/GHSA-vh9h-29pq-r5m8
- https://access.redhat.com/security/cve/CVE-2026-32304
- https://bugzilla.redhat.com/show_bug.cgi?id=2447200
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32304.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z