Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxjr-mmjv-4gpg

Опубликовано: 21 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

Lodash has Prototype Pollution Vulnerability in _.unset and _.omit functions

Impact

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.

The issue permits deletion of properties but does not allow overwriting their original behavior.

Patches

This issue is patched on 4.17.23.

Пакеты

Наименование

lodash

npm
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.17.22

4.17.23

Наименование

lodash.unset

npm
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.5.2

Отсутствует

Наименование

lodash-es

npm
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.17.22

4.17.23

Наименование

lodash-amd

npm
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.17.22

4.17.23

EPSS

Процентиль: 19%
0.0006
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

ubuntu
14 дней назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

nvd
14 дней назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

debian
14 дней назад

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype poll ...

EPSS

Процентиль: 19%
0.0006
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-1321