{"id":"CVE-2026-33993","aliases":["GHSA-4mph-v827-f877"],"url":"https://o3.security/vulnerability/CVE-2026-33993","summary":"Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()","details":"Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation without filtering the `__proto__` key. When a PHP serialized payload contains `__proto__` as an array or object key, JavaScript's `__proto__` setter is invoked, replacing the deserialized object's prototype with attacker-controlled content. This enables property injection, for...in propagation of injected properties, and denial of service via built-in method override. This is distinct from the previously reported prototype pollution in `parse_str` (GHSA-f98m-q3hr-p5wq, GHSA-rxrv-835q-v5mh) — `unserialize` is a different function with no mitigation applied. Version 3.0.25 patches the issue.","published":"2026-03-27T22:14:03.495Z","modified":"2026-08-12T03:51:46.709576607Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"locutus","fixedVersion":"3.0.25"}],"fix":{"url":"https://github.com/locutusjs/locutus/commit/345a6211e1e6f939f96a7090bfeff642c9fcf9e4","label":"locutusjs/locutus@345a621"},"references":[{"type":"WEB","url":"https://github.com/locutusjs/locutus/releases/tag/v3.0.25"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33993.json"},{"type":"ADVISORY","url":"https://github.com/locutusjs/locutus/security/advisories/GHSA-4mph-v827-f877"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33993"},{"type":"FIX","url":"https://github.com/locutusjs/locutus/commit/345a6211e1e6f939f96a7090bfeff642c9fcf9e4"},{"type":"FIX","url":"https://github.com/locutusjs/locutus/pull/597"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.709576607Z"}}