CVE Database
/

CVE-2026-2950

Back to search

CVE-2026-2950

Published: Mar 31, 2026

Modified: Apr 1, 2026

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype. The issue permits deletion of prototype properties but does not allow overwriting their original behavior. Patches: This issue is patched in 4.18.0. Workarounds: None. Upgrade to the patched version.

VendorProductVersions

lodash

lodash

affected
4.17.23 - < 4.18.0
unaffected
4.18.0

lodash

lodash-es

affected
4.17.23 - < 4.18.0
unaffected
4.18.0

lodash

lodash-amd

affected
4.17.23 - < 4.18.0
unaffected
4.18.0

lodash

lodash.unset

affected
4.0.0 - < 4.18.0
unaffected
4.18.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now