PT-2026-3846 · Lodash+3 · Lodash+3

·

CVE-2025-13465

·

Published

2025-01-01

·

Updated

2026-07-31

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Lodash versions 4.0.0 through 4.17.22
Description Lodash versions 4.0.0 through 4.17.22 are susceptible to prototype pollution within the .unset and .omit functions. An attacker can leverage crafted paths to trigger the deletion of methods from global prototypes. The issue allows for property deletion but does not permit modification of the original behavior of those properties.
Recommendations Update to Lodash version 4.17.23 or later.

Exploit

Fix

DoS

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:18480
ALSA-2026:18868
ALSA-2026:2438
ALSA-2026:2452
BDU:2026-09405
CVE-2025-13465
GHSA-F23M-R3PF-42RH
GHSA-XXJR-MMJV-4GPG
OPENSUSE-SU-2026:10124-1
OPENSUSE-SU-2026:10147-1
OPENSUSE-SU-2026:10148-1
OPENSUSE-SU-2026:10149-1
OPENSUSE-SU-2026:10150-1
OPENSUSE-SU-2026:10154-1
OPENSUSE-SU-2026:10155-1
OPENSUSE-SU-2026:11126-1
OPENSUSE-SU-2026:20177-1
OPENSUSE-SU-2026:20181-1
OPENSUSE-SU-2026:20182-1
OPENSUSE-SU-2026:20185-1
OPENSUSE-SU-2026:20244-1
OPENSUSE-SU-2026:20251-1
OPENSUSE-SU-2026:20336-1
OPENSUSE-SU-2026:21399-1
RHSA-2026:18480
RHSA-2026:18868
RHSA-2026:24331
RHSA-2026:2438
RHSA-2026:2452
RHSA-2026:2462
RHSA-2026:2465
RHSA-2026:2469
RHSA-2026:2484
RHSA-2026:2816
RHSA-2026:2817
RHSA-2026:2818
RHSA-2026:2819
RHSA-2026:33371
RHSA-2026:3958
SUSE-SU-2026:0379-1
SUSE-SU-2026:0396-1
SUSE-SU-2026:0397-1
SUSE-SU-2026:1008-1
SUSE-SU-2026:1013-1
SUSE-SU-2026:1035-1
SUSE-SU-2026:1524-1
SUSE-SU-2026:20232-1
SUSE-SU-2026:20236-1
SUSE-SU-2026:20237-1
SUSE-SU-2026:20336-1
SUSE-SU-2026:20337-1
SUSE-SU-2026:20338-1
SUSE-SU-2026:20454-1
SUSE-SU-2026:20494-1
SUSE-SU-2026:20538-1
SUSE-SU-2026:20540-1
SUSE-SU-2026:20576-1
SUSE-SU-2026:20580-1
SUSE-SU-2026:20650-1
SUSE-SU-2026:20653-1
SUSE-SU-2026:20688-1
SUSE-SU-2026:20695-1
SUSE-SU-2026:22770-1
SUSE-SU-2026:22837-1
USN-8411-1

Affected Products

Linuxmint
Lodash
Rocky Linux
Ubuntu