CVE-2026-2950 identifies a prototype pollution vulnerability in Lodash versions 4.17.23 and earlier, affecting the _.unset and _.omit functions. An attacker can bypass a previous fix by using array-wrapped path segments, allowing the deletion of properties from built-in prototypes like Object.prototype, though not overwriting their original behavior. This medium-severity issue (CVSS 6.5) has a low attack complexity and can be exploited over the network, potentially impacting application integrity and availability. There is no evidence of active exploitation or public exploit code, with only limited community discussion noted. Users are advised to upgrade to Lodash version 4.18.0, which contains the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.17.23CPE matchmatch criteria | cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.17.23CPE matchmatch criteria | cpe:2.3:a:lodash:lodash-amd:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.17.23CPE matchmatch criteria | cpe:2.3:a:lodash:lodash-es:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0CPE matchmatch criteria | cpe:2.3:a:lodash:lodash.unset:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.