CVE-2026-2950

Source
https://cve.org/CVERecord?id=CVE-2026-2950
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-2950.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-2950
Aliases
Downstream
Related
Published
2026-03-31T19:18:35.796Z
Modified
2026-05-18T05:59:45.591927890Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Details

Impact:

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.

The issue permits deletion of prototype properties but does not allow overwriting their original behavior.

Patches:

This issue is patched in 4.18.0.

Workarounds:

None. Upgrade to the patched version.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2950.json",
    "cna_assigner": "openjs",
    "cwe_ids": [
        "CWE-1321"
    ]
}
References

Affected packages

Git / github.com/lodash/lodash

Affected ranges

Type
GIT
Repo
https://github.com/lodash/lodash
Events

Affected versions

4.*
4.0.0-npm-packages
4.0.1-npm-packages
4.0.2-npm-packages
4.0.3-npm-packages
4.0.4-npm-packages
4.0.5-npm-packages
4.0.6-npm-packages
4.0.7-npm-packages
4.0.8-npm-packages
4.0.9-npm-packages
4.1.0-npm-packages
4.1.1-npm-packages
4.1.2-npm-packages
4.1.3-npm-packages
4.1.4-npm-packages
4.1.5-npm-packages
4.10.0-npm-packages
4.10.1-npm-packages
4.10.2-npm-packages
4.11.0-npm-packages
4.11.1-npm-packages
4.11.2-npm-packages
4.12.0-npm-packages
4.12.1-npm-packages
4.13.0-npm-packages
4.14.0-npm-packages
4.15.0-npm-packages
4.2.0-npm-packages
4.2.1-npm-packages
4.2.2-npm-packages
4.2.3-npm-packages
4.2.4-npm-packages
4.2.5-npm-packages
4.3.0-npm-packages
4.3.1-npm-packages
4.3.2-npm-packages
4.3.3-npm-packages
4.3.4-npm-packages
4.3.5-npm-packages
4.4.0-npm-packages
4.4.1-npm-packages
4.4.2-npm-packages
4.4.3-npm-packages
4.5.0-npm-packages
4.5.1-npm-packages
4.5.2-npm-packages
4.5.3-npm-packages
4.5.4-npm-packages
4.5.5-npm-packages
4.5.6-npm-packages
4.5.7-npm-packages
4.6.0-npm-packages
4.6.1-npm-packages
4.6.2-npm-packages
4.7.0-npm-packages
4.7.1-npm-packages
4.8.0-npm-packages
4.8.1-npm-packages
4.9.0-npm-packages
4.9.1-npm-packages

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-2950.json"