IM
IronMonkey Threat Research

CVE-2025-13465 MEDIUM

Published: 2026-01-21 | Last Modified: 2026-06-02 | Status: Modified

Description

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

Additional Descriptions (1)

Las versiones de Lodash 4.0.0 a 4.17.22 son vulnerables a la contaminación de prototipos en las funciones _.unset y _.omit. Un atacante puede pasar rutas manipuladas que hacen que Lodash elimine métodos de prototipos globales. El problema permite la eliminación de propiedades, pero no permite sobrescribir su comportamiento original. Este problema está parcheado en 4.17.23

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Base Score: 6.9 (MEDIUM)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityLOW
Vulnerability AvailabilityLOW
Subsequent ConfidentialityHIGH
Subsequent IntegrityHIGH
Subsequent AvailabilityHIGH

Source: ce714d77-add3-4f53-aff5-83d477b104bb

Type: Secondary

Weaknesses

Source Type Description
ce714d77-add3-4f53-aff5-83d477b104bb Secondary
en CWE-1321

Affected Products

Vendor Product Version Update Type
lodash lodash * <built-in method update of dict object at 0x7f76027f7140> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*

References

Notification
Message here