Lodash < 4.18.0 Multiple Vulnerabilities

critical Web App Scanning Plugin ID 115562

Synopsis

Lodash < 4.18.0 Multiple Vulnerabilities

Description

According to its self-reported version number, Lodash is prior to 4.18.0. It is, therefore, affected by multiple vulnerabilities:

- A code injection vulnerability in the _.template function. The validation added for CVE-2021-23337 to the variable option was not applied to options.imports key names, which are passed to the same Function() constructor sink. An attacker able to control these key names can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, inherited properties were merged into imports, allowing polluted Object.prototype keys to reach the sink. (CVE-2026-4800)

- A prototype pollution vulnerability in the _.unset and _.omit functions. The fix for CVE-2025-13465 only guarded string path segments, an attacker can bypass it by wrapping path segments in arrays, allowing the deletion of properties from built-in prototypes such as Object.prototype, Number.prototype and String.prototype. The issue permits deletion of properties but does not allow overwriting their original behavior. (CVE-2026-2950)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Lodash version 4.18.0 or later.

See Also

https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh

https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc

Plugin Details

Severity: Critical

ID: 115562

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.35

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-4800

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-4800

Vulnerability Information

CPE: cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 3/30/2026

Reference Information

CVE: CVE-2026-2950, CVE-2026-4800