CVE-2026-32304
Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94, CWE-88
- Affected
- locutus/locutus
- Source
- security-advisories@github.com
References
- https://github.com/locutusjs/locutus/releases/tag/v3.0.14Product, Release Notes
- https://github.com/locutusjs/locutus/security/advisories/GHSA-vh9h-29pq-r5m8Exploit, Mitigation, Patch, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-32304
- https://bugzilla.redhat.com/show_bug.cgi?id=2447200
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32304.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.