Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://security.netapp.com/advisory/ntap-20210312-0006/
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
https://github.com/GuardBee/guardbee-mcp-dependency-auditor
https://github.com/Adityag025/blast-radius
https://github.com/zachary8138/node-cve-scan
https://github.com/yohanness16/cve_checker
https://github.com/high-tech-r/quiet-cve
https://github.com/abdulhanan-fauree/supply-chain-xray
https://github.com/Kerneth/stack-radar
https://github.com/birdai1/git-dependency-leak
https://github.com/1816x/Vulnerability-Triage-Agent
https://github.com/clidey/deptrust
https://github.com/Jeneidi/safedeps
https://github.com/mstampfli/cve2detect
https://github.com/vishal755/cve-remediation-project
https://github.com/RP-Digital-Innovations/context-snipe
https://github.com/wardsvelds2l/cve-watch
https://github.com/chrisgillham/oss-trust-framework
https://github.com/wudiqingshuidawang/depshield
https://github.com/ishitharaj/CVE-analyzer
https://github.com/veronimo669/Lodash-CVE-poc
https://github.com/ReganHarrington/stackdiff
https://github.com/theocampos/gr4pe
https://github.com/clearcapabilities/agentic-security
https://github.com/4444J99/cve-watch
https://github.com/DivijJaswal/cve-triage-bot
https://github.com/AVX-Prathamesh-Nadkarni/CVE-Monitor
https://github.com/voidd0/depcheck
https://github.com/Nikhil-Ladha/cve-smasher-claude-plugin
https://github.com/glferreira-devsecops/cascavel-dependency-audit
https://github.com/annie-7554/shadowaudit
https://github.com/devanshkaria88/depshield-mcp
https://github.com/Ottersight/ottersight-cli
https://github.com/Noumenon-ai/cve-guard
https://github.com/khayashi4337/lodash.template-fixed
https://github.com/tommieseals/vendor-risk-monitor
https://github.com/clay-good/blastauri
https://github.com/abhishekrai43/VulScan-MCP
https://github.com/vBarbaros/security-faux-pas
https://github.com/graydonhope/VulnerabilityScanner
https://github.com/zenzue/supply-chain-cve-checker
https://github.com/m0d0ri205/SBOM-CVE-Lister-for-npm
https://github.com/advisories/GHSA-8p5q-j9m2-g8wr
https://github.com/p-rog/cve-analyser
https://github.com/advisories/GHSA-35jh-r3h4-6jhm
https://snyk.io/vuln/SNYK-JS-LODASH-1040724
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930
https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932
https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851