Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-r5fr-rjxr-66jc

4 месяца назад

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19167

около 1 месяца назад

ELSA-2026-19167: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10713

3 месяца назад

ELSA-2026-10713: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10710

3 месяца назад

ELSA-2026-10710: pcs security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:24331

около 2 месяцев назад

Important: cockpit-image-builder security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
1%
Низкий
4 месяца назад
github логотип
GHSA-r5fr-rjxr-66jc

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19167

ELSA-2026-19167: pcs security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-10713

ELSA-2026-10713: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-10710

ELSA-2026-10710: pcs security update (IMPORTANT)

3 месяца назад
rocky логотип
RLSA-2026:24331

Important: cockpit-image-builder security update

около 2 месяцев назад

Уязвимостей на страницу