Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

locutusjs — Vulnerabilities & Security Advisories 5

Browse all 5 CVE security advisories affecting locutusjs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Locutusjs is a JavaScript library providing PHP-compatible functions for Node.js environments, commonly used for code migration and compatibility. Historically, it has faced vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, primarily through insecure input handling and flawed function implementations. The library's security issues often stem from its goal of emulating PHP's behavior without proper sanitization. Five CVEs have been recorded, highlighting risks in functions that process untrusted data. While no major public incidents have been widely reported, the consistent pattern of vulnerabilities suggests developers should implement additional input validation and consider alternatives for security-sensitive applications.

Top products by locutusjs: locutus

This page lists every published CVE security advisory associated with locutusjs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.