{"schema_version":"1.9.0","id":"GHSA-f23m-r3pf-42rh","published":"2026-04-01T23:50:27Z","modified":"2026-09-10T03:50:44.050013812Z","aliases":["CVE-2025-13465","CVE-2026-2950","GHSA-xxjr-mmjv-4gpg"],"summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","details":"### Impact\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the `_.unset` and `_.omit` functions. The fix for [CVE-2025-13465](https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as `Object.prototype`, `Number.prototype`, and `String.prototype`.\n\nThe issue permits deletion of prototype properties but does not allow overwriting their original behavior.\n\n### Patches\n\nThis issue is patched in 4.18.0.\n\n### Workarounds\n\nNone. Upgrade to the patched version.","affected":[{"package":{"name":"lodash","ecosystem":"npm","purl":"pkg:npm/lodash"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.18.0"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.17.23","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"}},{"package":{"name":"lodash-es","ecosystem":"npm","purl":"pkg:npm/lodash-es"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.18.0"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.17.23","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"}},{"package":{"name":"lodash-amd","ecosystem":"npm","purl":"pkg:npm/lodash-amd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.18.0"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.17.23","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"}},{"package":{"name":"lodash.unset","ecosystem":"npm","purl":"pkg:npm/lodash.unset"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.18.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"}}],"references":[{"type":"WEB","url":"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh"},{"type":"WEB","url":"https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2950"},{"type":"PACKAGE","url":"https://github.com/lodash/lodash"}],"database_specific":{"cwe_ids":["CWE-1321"],"github_reviewed":true,"github_reviewed_at":"2026-04-01T23:50:27Z","nvd_published_at":"2026-03-31T20:16:26Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}