ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-4800
+1 in the same advisory: …2950
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

NVD description · AI analysis pending
9.8
group max
3%
  • lodash lodash
  • lodash lodash-amd
  • lodash lodash-es
  • +1 more
CVE-2025-13465
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions.

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

NVD description · AI analysis pending
6.92%
  • lodash lodash
CVE-2021-23337
+1 in the same advisory: …28500
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

NVD description · AI analysis pending
7.2
group max
21% PoC ×6
  • lodash lodash
  • lodash banking corporate lending process management
  • lodash banking credit facilities process management
  • +1 more
CVE-2020-8203
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

NVD description · AI analysis pending
7.45% PoC
  • lodash lodash
  • lodash banking corporate lending process management
  • lodash banking credit facilities process management
  • +1 more
CVE-2019-10744
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution.

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

NVD description · AI analysis pending
9.15% PoC
  • lodash lodash
  • lodash active iq unified manager
  • lodash service level manager
  • +1 more
CVE-2019-1010266
lodash prior to 4.17.11 is affected by:

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.

NVD description · AI analysis pending
6.53% PoC
  • lodash lodash
CVE-2018-16487
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

NVD description · AI analysis pending
5.62% PoC
  • lodash lodash
CVE-2018-3721
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, wh

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

NVD description · AI analysis pending
6.52% PoC
  • lodash lodash
  • lodash active iq unified manager
  • lodash system manager