CVE-2026-4800 is a high-severity code injection vulnerability (CVSS 8.1) impacting the _.template function, where insufficient validation of options.imports key names allows for arbitrary code execution during template compilation. This remote vulnerability has high attack complexity but requires no privileges or user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While there are no known public exploits, active exploitation, or KEV listing, the vulnerability has received minor community discussion. Users should upgrade to version 4.18.0 to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.18.0CPE matchmatch criteria | cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.18.0CPE matchmatch criteria | cpe:2.3:a:lodash:lodash-amd:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.18.0CPE matchmatch criteria | cpe:2.3:a:lodash:lodash-es:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.18.0CPE matchmatch criteria | cpe:2.3:a:lodash:lodash.template:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.