lodash-rails
lodash for the Rails asset pipeline
Activity
- Latest release
- 5y ago
- Total releases
- 56
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Sep 11, 2012
| Version | Released | |
|---|---|---|
4.17.21
patch
| ||
4.17.15
patch
3 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.17.14
patch
3 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.17.11
patch
4 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.17.10
patch
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.17.5
patch
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.17.4
patch
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.17.2
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.16.6
patch
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.16.3
patch
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.16.4
patch
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.16.1
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.15.0
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.14.1
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.13.1
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.12.0
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.11.2
minor
7 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-1010266
GHSA-x5rq-j2xg-h7qm
SNYK-JS-LODASH-73639
Jul 19, 2019
Regular Expression Denial of Service (ReDoS) in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11. Affected versions
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
+ 1 more Show less
4.17.5
Fixed in
4.17.11
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.6.1
minor
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.5.1
minor
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.3.0
minor
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
4.0.0
major
6 CVEs
CVE-2020-28500
GHSA-29mw-wpgm-hmr9
Jan 06, 2022
Regular Expression Denial of Service (ReDoS) in lodash
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Steps to reproduce (provided by reporter Liyuan Chen):
Affected versions
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
+ 8 more Show less
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 29, 2025 · Source: OSV.dev
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.10.1
patch
5 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.10.0
minor
5 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.9.3
minor
5 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.7.0
minor
5 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8203
GHSA-p6mc-m468-83gw
Jul 15, 2020
Prototype Pollution in lodash
7.4
/ 10
High
Network
High
None
None
Unchanged
None
High
High
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances. Affected versions
3.10.0
3.10.1
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
+ 12 more Show less
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.19
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.6.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.5.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.4.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.3.1.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.3.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.3.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.2.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
3.1.0
major
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.4.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.4.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.3.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.2.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.2.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.1.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
2.0.0
major
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.3.1
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.2.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.2.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.1.1
patch
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.1.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.0.1
major
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.0.0.rc.3
pre
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.0.0.rc.2
pre
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
1.0.0.rc.1
pre
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev | ||
0.10.0
minor
4 CVEs
CVE-2021-23337
GHSA-35jh-r3h4-6jhm
CVE-2026-4800
GHSA-r5fr-rjxr-66jc
May 06, 2021
Command Injection in lodash
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 43 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.14
4.17.15
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.21
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-10744
GHSA-jf85-cpcp-j695
SNYK-JS-LODASH-450202
Jul 10, 2019
Prototype Pollution in lodash
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Versions of RecommendationUpdate to version 4.17.12 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 41 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.11
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.12
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2018-16487
GHSA-4xc9-xhrj-v574
Feb 07, 2019
Prototype Pollution in lodash
High
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.11 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 40 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.10
4.17.2
4.17.4
4.17.5
4.3.0
4.5.1
4.6.1
Fixed in
4.17.11
References
Updated Aug 12, 2025 · Source: OSV.dev
CVE-2018-3721
GHSA-fvqr-27wr-82fm
Jul 26, 2018
Prototype Pollution in lodash
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
Versions of The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of RecommendationUpdate to version 4.17.5 or later. Affected versions
0.10.0
0.7.0
0.8.1
0.8.2
0.9.0
0.9.1
0.9.2
1.0.0.rc.1
1.0.0.rc.2
1.0.0.rc.3
1.0.1
1.1.0
+ 38 more Show less
1.1.1
1.2.0
1.2.1
1.3.1
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.4.0
2.4.1
3.1.0
3.10.0
3.10.1
3.2.0
3.3.0
3.3.1
3.3.1.1
3.4.0
3.5.0
3.6.0
3.7.0
3.9.3
4.0.0
4.11.2
4.12.0
4.13.1
4.14.1
4.15.0
4.16.1
4.16.3
4.16.4
4.16.6
4.17.2
4.17.4
4.3.0
4.5.1
4.6.1
Fixed in
4.17.5
References
Updated Aug 12, 2025 · Source: OSV.dev |