CVE-2026-2950

EUVD-2026-17591
Impact:

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.

The issue permits deletion of prototype properties but does not allow overwriting their original behavior.

Patches:

This issue is patched in 4.18.0.

Workarounds:

None. Upgrade to the patched version.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 24.34%
Affected Products (NVD)
VendorProductVersion
lodashlodash
4.0.0 ≤
𝑥
< 4.17.23
lodashlodash-amd
4.0.0 ≤
𝑥
< 4.17.23
lodashlodash-es
4.0.0 ≤
𝑥
< 4.17.23
lodashlodash.unset
4.0.0 ≤
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-lodash
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
4.17.21+dfsg+~cs8.31.173-1+deb11u1
fixed
forky
4.18.1+dfsg-3
fixed
sid
4.18.1+dfsg1-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-lodash
bionic
Fixed 4.17.4+dfsg-1ubuntu0.1~esm1
released
focal
Fixed 4.17.15+dfsg-2ubuntu0.1~esm1
released
jammy
Fixed 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1
released
noble
Fixed 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1
released
questing
Fixed 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1
released
resolute
Fixed 4.17.23+dfsg-1ubuntu0.1~esm1
released
xenial
ignored