CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lodash 5Lodash Lodash AmdLodash Es+2 moreJul 24, 2026 Mar 31, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both path...Show more |
1Lodash 4Lodash Lodash AmdLodash Es+1 moreJul 24, 2026 Mar 31, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gp...Show more |