Lodash is a widely embedded utility library that provides functional programming helpers across countless JavaScript applications and frameworks, despite its narrow product footprint. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs through prototype-pollution flaws, code-injection risks, and uncontrolled resource consumption that reflect the library's deep involvement in object manipulation and dynamic code evaluation. Defenders should prioritize inventory of applications bundling this library, since a single flaw in Lodash can propagate across an enormous supply-chain footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lodash over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23337HIGH Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Feb 15, 2021 | 7.2 | 49 | NO | YES |
CVE-2026-4800CRITICAL Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation | Mar 31, 2026 | 9.8 | 42 | NO | NO |
CVE-2019-10744CRITICAL Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype usin | Jul 26, 2019 | 9.1 | 31 | NO | NO |
CVE-2025-13465MEDIUM Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete met | Jan 21, 2026 | 5.3 | 29 | NO | NO |
CVE-2020-8203HIGH Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | Jul 15, 2020 | 7.4 | 27 | NO | NO |
CVE-2026-2950MEDIUM Impact:
Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodas | Mar 31, 2026 | 5.3 | 24 | NO | NO |
CVE-2019-1010266MEDIUM lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker | Jul 17, 2019 | 6.5 | 24 | NO | NO |
CVE-2018-3721MEDIUM lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicio | Jun 7, 2018 | 6.5 | 23 | NO | NO |
CVE-2020-28500MEDIUM Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | Feb 15, 2021 | 5.3 | 21 | NO | NO |
CVE-2018-16487MEDIUM A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object | Feb 1, 2019 | 5.6 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lodash.
Media articles that mention a CVE ID that affects a product developed by Lodash — matched by CVE ID, not by vendor name.