CVE-2025-13465
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P
- EPSS probability
- 1.63%
- CWE
- CWE-1321
- Published
- 2026-01-21
- Last modified
- 2026-09-14
Affected products
- Lodash Lodash
- Lodash-amd Lodash-amd
- lodash-es lodash-es
- lodash.unset lodash.unset
- npm lodash
- npm lodash.unset
- npm lodash-es
- npm lodash-amd
Weakness type
Related vulnerabilities
- CVE-2011-10019 — Spreecommerce < 0.60.2 Search Parameter RCE
- CVE-2024-21512 — Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitizatio
- CVE-2026-34621 — Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-32621 — Apollo Federation has prototype pollution via incomplete key sanitization
- CVE-2025-25015 — Kibana arbitrary code execution via prototype pollution
- CVE-2026-33994 — Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
- CVE-2026-21854 — Tarkov Data Manager Authentication Bypass vulnerability
- CVE-2026-33696 — n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE