Executive brief
Lodash, a widely used JavaScript utility library, is vulnerable to a security flaw that allows attackers to delete properties from global object prototypes. By providing specially crafted input to certain functions, an attacker could potentially disable core application features or cause service instability. This issue is a bypass of a previous security fix and affects applications that process untrusted user input through Lodash's data manipulation tools.
Technical details
A prototype pollution vulnerability exists in Lodash's _.unset and _.omit functions due to an incomplete fix for a previous vulnerability (CVE-2025-13465). While the previous fix guarded against string-based keys, attackers can bypass this by passing array-wrapped path segments. This allows an unauthenticated remote attacker to delete properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype. While this does not allow for property overwriting or direct code execution, it can lead to denial of service or application logic bypasses by removing essential methods. The issue is addressed in version 4.18.0.
Affected products
- lodash lodash >= 4.0.0, < 4.18.0
- lodash lodash-es >= 4.0.0, < 4.18.0
- lodash lodash-amd >= 4.0.0, < 4.18.0
- lodash lodash.unset >= 4.0.0, < 4.18.0
Timeline
- 2026-01-21: advisory: Initial advisory for related CVE-2025-13465 published
- 2026-03-31: disclosed: CVE-2026-2950 disclosed as a bypass of the previous fix
- 2026-03-31: patched: Fixed in version 4.18.0