CRITICAL9.8CVE-2026-32304Locutus vulnerable to RCE via unsanitized input in create_function() from 0, < 3.0.14
from 0, <= 2.0.11
from 0, < 2.0.12
HIGH8.1CVE-2026-29091locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection from 0, < 3.0.0
HIGH7.5Uncontrolled Resource Consumption in locutus
from 0, < 2.0.15
—Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
>= 2.0.39, < 3.0.25
—Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
from 0, < 3.0.25
—locutus is vulnerable to Prototype Pollution
>= 2.0.12, < 2.0.39