Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-r5fr-rjxr-66jc

4 месяца назад

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19167

около 1 месяца назад

ELSA-2026-19167: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10713

3 месяца назад

ELSA-2026-10713: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10710

3 месяца назад

ELSA-2026-10710: pcs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09406

4 месяца назад

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:24331

около 2 месяцев назад

Important: cockpit-image-builder security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-r5fr-rjxr-66jc

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
2%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
2%
Низкий
4 месяца назад
redhat логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
2%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
2%
Низкий
4 месяца назад
debian логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
2%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19167

ELSA-2026-19167: pcs security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-10713

ELSA-2026-10713: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-10710

ELSA-2026-10710: pcs security update (IMPORTANT)

3 месяца назад
fstec логотип
BDU:2026-09406

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
2%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:24331

Important: cockpit-image-builder security update

около 2 месяцев назад

Уязвимостей на страницу