CVE-2026-29091: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in locutusjs locutus
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array function implementation. The vulnerability allows an attacker to inject arbitrary JavaScript code into the application's runtime environment. This issue stems from an insecure implementation of the call_user_func_array function (and its wrapper call_user_func), which fails to properly validate all components of a callback array before passing them to eval(). This issue has been patched in version 3.0.0.
AI Analysis
Technical Summary
Locutus, a JavaScript library providing standard libraries from other languages, contained a remote code execution vulnerability in its call_user_func_array function implementation prior to version 3.0.0. The vulnerability arises from insecure use of eval() on callback arrays without proper validation, enabling attackers to inject arbitrary JavaScript code at runtime. This flaw is classified under CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code) and CWE-94 (Improper Control of Generation of Code). The issue has been addressed and fixed in locutus version 3.0.0.
Potential Impact
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript code remotely within the affected application environment, potentially leading to full compromise of the application, including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.1 (High), reflecting network attack vector, high impact on confidentiality, integrity, and availability, and requiring high attack complexity but no privileges or user interaction.
Mitigation Recommendations
An official fix is available in locutus version 3.0.0. Users and administrators should upgrade to version 3.0.0 or later to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
CVE-2026-29091: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in locutusjs locutus
Description
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array function implementation. The vulnerability allows an attacker to inject arbitrary JavaScript code into the application's runtime environment. This issue stems from an insecure implementation of the call_user_func_array function (and its wrapper call_user_func), which fails to properly validate all components of a callback array before passing them to eval(). This issue has been patched in version 3.0.0.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Locutus, a JavaScript library providing standard libraries from other languages, contained a remote code execution vulnerability in its call_user_func_array function implementation prior to version 3.0.0. The vulnerability arises from insecure use of eval() on callback arrays without proper validation, enabling attackers to inject arbitrary JavaScript code at runtime. This flaw is classified under CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code) and CWE-94 (Improper Control of Generation of Code). The issue has been addressed and fixed in locutus version 3.0.0.
Potential Impact
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript code remotely within the affected application environment, potentially leading to full compromise of the application, including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.1 (High), reflecting network attack vector, high impact on confidentiality, integrity, and availability, and requiring high attack complexity but no privileges or user interaction.
Mitigation Recommendations
An official fix is available in locutus version 3.0.0. Users and administrators should upgrade to version 3.0.0 or later to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-03T21:54:06.707Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-29091","vendor":"Red Hat"}]
Threat ID: 69ab1661c48b3f10ffba181e
Added to database: 03/06/2026, 18:01:05 UTC
Last enriched: 07/15/2026, 08:49:03 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.