QSearchQSearch

CVE-2025-13465

5.3 MEDIUM

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions

Published: 2026-01-21 · Last updated: 2026-06-02

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE
CWE-1321

Affected products

VendorProduct
lodashlodash

Description

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-48714 i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno (9.1 CRITICAL)
  • CVE-2026-48713 Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation ke... (9.1 CRITICAL)
  • CVE-2026-12209 A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10 (5.3 MEDIUM)
  • CVE-2026-12208 A weakness has been identified in jsonata-js jsonata up to 2.2.0 (5.3 MEDIUM)
  • CVE-2026-53609 ApostropheCMS is an open-source Node.js content management system (9.1 CRITICAL)