CVE-2021-23337

high

Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

References

https://github.com/GuardBee/guardbee-mcp-dependency-auditor

https://github.com/Adityag025/blast-radius

https://github.com/zachary8138/node-cve-scan

https://github.com/yohanness16/cve_checker

https://github.com/high-tech-r/quiet-cve

https://github.com/abdulhanan-fauree/supply-chain-xray

https://github.com/Kerneth/stack-radar

https://github.com/birdai1/git-dependency-leak

https://github.com/1816x/Vulnerability-Triage-Agent

https://github.com/luthfan-tech/-Go-dependency-security-auditor-with-60-CVEs-and-colourised-terminal-report

https://github.com/clidey/deptrust

https://github.com/Jeneidi/safedeps

https://github.com/mstampfli/cve2detect

https://github.com/vishal755/cve-remediation-project

https://github.com/RP-Digital-Innovations/context-snipe

https://github.com/wardsvelds2l/cve-watch

https://github.com/chrisgillham/oss-trust-framework

https://github.com/wudiqingshuidawang/depshield

https://github.com/ishitharaj/CVE-analyzer

https://github.com/veronimo669/Lodash-CVE-poc

https://github.com/ReganHarrington/stackdiff

https://github.com/theocampos/gr4pe

https://github.com/clearcapabilities/agentic-security

https://github.com/4444J99/cve-watch

https://github.com/DivijJaswal/cve-triage-bot

https://github.com/AVX-Prathamesh-Nadkarni/CVE-Monitor

https://github.com/voidd0/depcheck

https://github.com/Nikhil-Ladha/cve-smasher-claude-plugin

https://github.com/glferreira-devsecops/cascavel-dependency-audit

https://github.com/annie-7554/shadowaudit

https://github.com/devanshkaria88/depshield-mcp

https://github.com/Ottersight/ottersight-cli

https://github.com/Noumenon-ai/cve-guard

https://github.com/khayashi4337/lodash.template-fixed

https://github.com/tommieseals/vendor-risk-monitor

https://github.com/clay-good/blastauri

https://github.com/abhishekrai43/VulScan-MCP

https://github.com/vBarbaros/security-faux-pas

https://github.com/graydonhope/VulnerabilityScanner

https://github.com/zenzue/supply-chain-cve-checker

https://github.com/m0d0ri205/SBOM-CVE-Lister-for-npm

https://github.com/advisories/GHSA-8p5q-j9m2-g8wr

https://github.com/p-rog/cve-analyser

https://github.com/advisories/GHSA-35jh-r3h4-6jhm

https://snyk.io/vuln/SNYK-JS-LODASH-1040724

https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929

https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931

https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928

https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930

https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932

https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851

Details

Source: Mitre, NVD

Published: 2021-02-15

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.2241