VYPR

Lodash

by Lodash

npm: lodash

Source repositories

CVEs (10)

  • CVE-2026-4800HigMar 31, 2026
    risk 0.46cvss 8.1epss 0.03

    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an…

  • CVE-2021-23337HigFeb 15, 2021
    risk 0.42cvss 7.2epss 0.21

    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

  • CVE-2020-8203HigJul 15, 2020
    risk 0.42cvss 7.4epss 0.05

    Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

  • CVE-2026-2950MedMar 31, 2026
    risk 0.35cvss 6.5epss 0.00

    Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker…

  • CVE-2019-1010266MedJul 17, 2019
    risk 0.35cvss 6.5epss 0.03

    lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The…

  • CVE-2018-3721MedJun 7, 2018
    risk 0.35cvss 6.5epss 0.02

    lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of…

  • CVE-2018-16487MedFeb 1, 2019
    risk 0.30cvss 5.6epss 0.02

    A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

  • CVE-2025-13465MedJan 21, 2026
    risk 0.28cvss 5.3epss 0.02

    Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow…

  • CVE-2020-28500MedFeb 15, 2021
    risk 0.28cvss 5.3epss 0.07

    Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

  • CVE-2019-10744CriJul 26, 2019
    risk 0.00cvss 9.1epss 0.05

    Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.