<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:31:05 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337354</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337354</link>
      <description>EUVD-2026-337354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337354</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32304</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32304</link>
      <description>&lt;p&gt;Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2026-29091 which was call_user_func_array using eval() in v2.x. This finding affects create_function using new Function() in v3.x. This vulnerability is fixed in 3.0.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32304</guid>
    </item>
    <item>
      <title>GHSA-vh9h-29pq-r5m8 — Locutus vulnerable to RCE via unsanitized input in create_function()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vh9h-29pq-r5m8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: locutus&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `create_function(args, code)` function passes both parameters directly to the `Function` constructor without any sanitization, allowing arbitrary code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2026-29091 (GHSA-fp25-p6mj-qqg6) which was `call_user_func_array` using `eval()` in v2.x. This finding affects `create_function` using `new Function()` in v3.x.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`src/php/funchand/create_function.ts:17`:
```typescript
return new Function(...params, code)
```&lt;/p&gt;
&lt;p&gt;Zero input validation on either parameter.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```javascript
const { create_function } = require(&amp;#39;locutus/php/funchand/create_function&amp;#39;);
const rce = create_function(&amp;#39;&amp;#39;, &amp;#39;return require(&amp;#34;child_process&amp;#34;).execSync(&amp;#34;id&amp;#34;).toString()&amp;#39;);
console.log(rce());
// Output: uid=501(user) gid=20(staff) ...
```&lt;/p&gt;
&lt;p&gt;Confirmed on locutus v3.0.11, Node.js v24.13.1.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Full RCE when an attacker can control either argument to `create_function()`. 597K weekly npm downloads.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Remove `create_function` or replace `new Function()` with a safe alternative. PHP itself deprecated `create_function()` in PHP 7.2 for the same reason.&lt;/p&gt;
&lt;p&gt;## Response&lt;/p&gt;
&lt;p&gt;Thanks for the report.&lt;/p&gt;
&lt;p&gt;We confirmed that `php/funchand/create_function` was still present through `locutus@3.0.13` and that it exposed dynamic code execution via `new Function(...)`.&lt;/p&gt;
&lt;p&gt;While this was intended behavior, `create_function()` inherently needs to be unsafe in order for it to work, `create_function()` was deprecated in PHP 7.2 and removed in PHP 8.0.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: locutus&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `create_function(args, code)` function passes both parameters directly to the `Function` constructor without any sanitization, allowing arbitrary code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2026-29091 (GHSA-fp25-p6mj-qqg6) which was `call_user_func_array` using `eval()` in v2.x. This finding affects `create_function` using `new Function()` in v3.x.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`src/php/funchand/create_function.ts:17`:
```typescript
return new Function(...params, code)
```&lt;/p&gt;
&lt;p&gt;Zero input validation on either parameter.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```javascript
const { create_function } = require(&amp;#39;locutus/php/funchand/create_function&amp;#39;);
const rce = create_function(&amp;#39;&amp;#39;, &amp;#39;return require(&amp;#34;child_process&amp;#34;).execSync(&amp;#34;id&amp;#34;).toString()&amp;#39;);
console.log(rce());
// Output: uid=501(user) gid=20(staff) ...
```&lt;/p&gt;
&lt;p&gt;Confirmed on locutus v3.0.11, Node.js v24.13.1.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Full RCE when an attacker can control either argument to `create_function()`. 597K weekly npm downloads.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Remove `create_function` or replace `new Function()` with a safe alternative. PHP itself deprecated `create_function()` in PHP 7.2 for the same reason.&lt;/p&gt;
&lt;p&gt;## Response&lt;/p&gt;
&lt;p&gt;Thanks for the report.&lt;/p&gt;
&lt;p&gt;We confirmed that `php/funchand/create_function` was still present through `locutus@3.0.13` and that it exposed dynamic code execution via `new Function(...)`.&lt;/p&gt;
&lt;p&gt;While this was intended behavior, `create_function()` inherently needs to be unsafe in order for it to work, `create_function()` was deprecated in PHP 7.2 and removed in PHP 8.0.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vh9h-29pq-r5m8</guid>
    </item>
  </channel>
</rss>
