VDB
GHSA-r5fr-rjxr-66jc
GHSA-r5fr-rjxr-66jc
PUBLISHED
CVSS 8.100000381469727 HIGH
lodash vulnerable to Code Injection via `_.template` imports key names
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | lodash.template | 4.0.0, 4.0.0, 4.0.0 |
| npm | lodash-amd | 4.0.0, 4.0.0, 4.0.0 |
| npm | lodash | 4.0.0, 4.0.0, 4.0.0 |
| npm | lodash-es | 4.0.0, 4.0.0, 4.0.0 |
Timeline
- Apr 1, 2026 CVE Published
- Apr 9, 2026 Security Advisory
References
- https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc url
- https://nvd.nist.gov/vuln/detail/CVE-2026-4800 advisory
- https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c url
- https://cna.openjsf.org/security-advisories.html url
- https://github.com/advisories/GHSA-35jh-r3h4-6jhm advisory
- https://github.com/lodash/lodash package