<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T01:35:04.842179+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337354</id>
    <title>EUVD-2026-337354</title>
    <updated>2026-10-08T01:35:04.892582+00:00</updated>
    <content>EUVD-2026-337354</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32304</id>
    <title>fkie_cve-2026-32304</title>
    <updated>2026-10-08T01:35:04.892622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vh9h-29pq-r5m8</id>
    <title>GHSA-vh9h-29pq-r5m8 — Locutus vulnerable to RCE via unsanitized input in create_function()</title>
    <updated>2026-10-08T01:35:04.892656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: locutus</p>
<p>## Summary</p>
<p>The `create_function(args, code)` function passes both parameters directly to the `Function` constructor without any sanitization, allowing arbitrary code execution.</p>
<p>This is distinct from CVE-2026-29091 (GHSA-fp25-p6mj-qqg6) which was `call_user_func_array` using `eval()` in v2.x. This finding affects `create_function` using `new Function()` in v3.x.</p>
<p>## Root Cause</p>
<p>`src/php/funchand/create_function.ts:17`:
```typescript
return new Function(...params, code)
```</p>
<p>Zero input validation on either parameter.</p>
<p>## PoC</p>
<p>```javascript
const { create_function } = require('locutus/php/funchand/create_function');
const rce = create_function('', 'return require("child_process").execSync("id").toString()');
console.log(rce());
// Output: uid=501(user) gid=20(staff) ...
```</p>
<p>Confirmed on locutus v3.0.11, Node.js v24.13.1.</p>
<p>## Impact</p>
<p>Full RCE when an attacker can control either argument to `create_function()`. 597K weekly npm downloads.</p>
<p>## Suggested Fix</p>
<p>Remove `create_function` or replace `new Function()` with a safe alternative. PHP itself deprecated `create_function()` in PHP 7.2 for the same reason.</p>
<p>## Response</p>
<p>Thanks for the report.</p>
<p>We confirmed that `php/funchand/create_function` was still present through `locutus@3.0.13` and that it exposed dynamic code execution via `new Function(...)`.</p>
<p>While this was intended behavior, `create_function()` inherently needs to be unsafe in order for it to work, `create_function()` was deprecated in PHP 7.2 and removed in PHP 8.0.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vh9h-29pq-r5m8"/>
  </entry>
</feed>
