CVE-2026-29091 | locutusjs locutus up to 2.x eval eval injection (GHSA-fp25-p6mj-qqg6)
A vulnerability was found in locutusjs locutus up to 2.x. It has been rated as problematic. This vulnerability affects the function eval. The manipulation leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is uniquely identified as CVE-2026-29091. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.