Vulnerability GHSA-vc8f-x9pp-wf5p

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 months ago
March 27, 2026 at 05:58 PM UTC
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
2.0.39 - 3.0.24
2.0.39 - 3.0.24

Summary

Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521

Details

Summary

A prototype pollution vulnerability exists in the parse_str function of the npm package locutus. An attacker can pollute Object.prototype by overriding RegExp.prototype.test and then passing a crafted query string to parse_str, bypassing the prototype pollution guard.

This vulnerability stems from an incomplete fix for CVE-2026-25521. The CVE-2026-25521 patch replaced the String.prototype.includes()-based guard with a RegExp.prototype.test()-based guard. However, RegExp.prototype.test is itself a writable prototype method that can be overridden, making the new guard bypassable in the same way as the original — trading one hijackable built-in for another.

Package

locutus (npm)

Affected versions

= 2.0.39, <= 3.0.24

Tested and confirmed vulnerable on 2.0.39 and 3.0.24 (latest). Version 2.0.38 (pre-fix) uses a different guard (String.prototype.includes) and is not affected by this specific bypass.

The locutus team is treating this as a real package vulnerability with patched version 3.0.25. The vulnerable range should end at < 3.0.25.

Impacted packages

Timeline

Published
6 months ago
March 27, 2026 at 05:58 PM UTC
Fixed (3.0.25)
6 months ago
March 25, 2026 at 12:44 PM UTC
Last Modified
6 months ago
March 30, 2026 at 08:34 PM UTC