Executive brief
Underscore is a widely-used JavaScript library that provides utility functions for common programming tasks. The _.flatten and _.isEqual functions lack depth limits on recursion, allowing deeply nested data structures to trigger stack overflow errors and crash applications. This vulnerability is particularly dangerous for server applications and APIs that process untrusted user input, as attackers can submit malicious data to cause service outages.
Technical details
The vulnerability exists in the _.flatten and _.isEqual functions, which use unbounded recursion without enforcing a maximum depth limit. An attacker can craft deeply nested JSON objects or arrays (approximately 4500 levels deep) that, when parsed and passed to either function, trigger a RangeError stack overflow. Exploitation requires: (1) untrusted input used to create nested data structures via JSON.parse with no depth validation, (2) the resulting structure passed to _.flatten or _.isEqual, and (3) for _.isEqual, a code path where two distinct but structurally equivalent objects are compared. The exception is not caught, causing the application to crash. The issue affects all versions up to and including 1.13.7 and is patched in version 1.13.8 or later. Workarounds include enforcing a maximum nesting depth of 1000 (or lower on constrained systems) when parsing untrusted input, or passing a depth limit to _.flatten.
Affected products
- Underscore.js Underscore <=1.13.7
Timeline
- 2026-03-03: disclosed
- 2026-03-03: patched: Version 1.13.8 released with fix