CVE-2026-25521 | locutusjs locutus up to 2.0.38 prototype pollution (GHSA-rxrv-835q-v5mh)
A vulnerability categorized as problematic has been discovered in locutusjs locutus up to 2.0.38. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is tracked as CVE-2026-25521. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.