Junglewise Threat Intelligence

CVE-2025-13465: Lodash prototype pollution in _.unset and _.omit functions

CVE-2025-13465 · Severity: medium · CVSS 6.5 · Published 2026-01-21

Technologies: Lodash-Amd, lodash (npm), lodash-es (npm). Vendors: Lodash, npm.

Executive brief

Lodash is a widely used JavaScript utility library that helps developers manage data and perform common programming tasks. A security flaw in certain versions allows an attacker to delete important internal functions from the application's environment. This can lead to application crashes or unpredictable behavior, potentially disrupting services that rely on this library.

Technical details

A prototype pollution vulnerability exists in Lodash's `_.unset` and `_.omit` functions due to improper path validation. By passing specially crafted paths (e.g., using `__proto__`), a remote attacker can trigger the deletion of properties or methods from global object prototypes. While this specific flaw does not allow for property overwriting or direct code execution, it can be used to cause a denial-of-service (DoS) condition by removing essential built-in methods. The issue is addressed in version 4.17.23 by improving path sanitization.

Affected products

  • Lodash lodash >= 4.0.0, <= 4.17.22
  • Lodash lodash-es >= 4.0.0, <= 4.17.22
  • Lodash lodash-amd >= 4.0.0, <= 4.17.22
  • Lodash lodash.unset >= 4.0.0, <= 4.5.2

Timeline

  • 2026-01-21: disclosed
  • 2026-01-21: advisory
  • 2026-01-21: patched: Patched in version 4.17.23

References

Related threats