Back

MEDIUM

Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()

Published Mar 27, 2026

Description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation without filtering the `__proto__` key. When a PHP serialized payload contains `__proto__` as an array or object key, JavaScript's `__proto__` setter is invoked, replacing the deserialized object's prototype with attacker-controlled content. This enables property injection, for...in propagation of injected properties, and denial of service via built-in method override. This is distinct from the previously reported prototype pollution in `parse_str` (GHSA-f98m-q3hr-p5wq, GHSA-rxrv-835q-v5mh) — `unserialize` is a different function with no mitigation applied. Version 3.0.25 patches the issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 27, 2026
Updated Mar 30, 2026
Reserved Mar 24, 2026

CISA Vulnrichment

Updated Mar 30, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 27, 2026
Bugzilla 2452536

ENISA EUVD

Assigner GitHub_M
Published Mar 27, 2026
Updated Mar 30, 2026