Vulnerability GHSA-h86x-mv66-gr5q
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 years ago
July 26, 2021 at 09:21 PM UTC
OS Command Injection in Locutus
0.0.1 - 2.0.11
0.0.1 - 2.0.11
Summary
OS Command Injection in Locutus
Details
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
6 months ago
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
2.0.39 - 3.0.24 GHSA-vc8f-x9pp-wf5p
2.0.39 - 3.0.24 GHSA-vc8f-x9pp-wf5p
Medium Risk
6 months ago
Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
0.0.1 - 3.0.24 GHSA-4mph-v827-f877
0.0.1 - 3.0.24 GHSA-4mph-v827-f877
Critical
6 months ago
Locutus vulnerable to RCE via unsanitized input in create_function()
0.0.1 - 3.0.13 GHSA-vh9h-29pq-r5m8
0.0.1 - 3.0.13 GHSA-vh9h-29pq-r5m8
High Risk
7 months ago
locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection
0.0.1 - 2.0.39 GHSA-fp25-p6mj-qqg6
0.0.1 - 2.0.39 GHSA-fp25-p6mj-qqg6
Critical
8 months ago
locutus is vulnerable to Prototype Pollution
2.0.12 - 2.0.38 GHSA-rxrv-835q-v5mh
2.0.12 - 2.0.38 GHSA-rxrv-835q-v5mh
Impacted packages
Timeline
Published
5 years ago
July 26, 2021 at 09:21 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:02 AM UTC