VDB
Sign up
MEDIUM6.5

GHSA-f23m-r3pf-42rh

lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Quick fix

GHSA-f23m-r3pf-42rh — lodash: upgrade to the fixed version with the command below.

npm install lodash@4.18.0

Details

### Impact

Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the `_.unset` and `_.omit` functions. The fix for [CVE-2025-13465](https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as `Object.prototype`, `Number.prototype`, and `String.prototype`.

The issue permits deletion of prototype properties but does not allow overwriting their original behavior.

### Patches

This issue is patched in 4.18.0.

### Workarounds

None. Upgrade to the patched version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lodash
Introduced in: 0Fixed in: 4.18.0
Fixnpm install lodash@4.18.0
npm/lodash-es
Introduced in: 0Fixed in: 4.18.0
Fixnpm install lodash-es@4.18.0
npm/lodash-amd
Introduced in: 0Fixed in: 4.18.0
Fixnpm install lodash-amd@4.18.0
npm/lodash.unset
Introduced in: 4.0.0Fixed in: 4.18.0
Fixnpm install lodash.unset@4.18.0

References