chore(deps): update dependency lodash to v4.18.1 [security] - #94
Open
sc-renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency lodash to v4.18.1 [security]#94sc-renovate[bot] wants to merge 1 commit into
sc-renovate[bot] wants to merge 1 commit into
Conversation
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
from
April 7, 2026 18:33
dbe8529 to
d854d3f
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
6 times, most recently
from
April 29, 2026 19:06
d47d81c to
d018ce2
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
3 times, most recently
from
May 4, 2026 02:44
a00d749 to
3a57cb3
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
May 14, 2026 02:23
c9f4982 to
64b461d
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
May 22, 2026 04:11
aecde2a to
71bbc20
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
June 1, 2026 02:30
5537ac5 to
4caaa23
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
June 9, 2026 02:43
da94db7 to
28b214f
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
June 18, 2026 16:13
e2f6823 to
5a9671a
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
June 30, 2026 05:08
567ff25 to
7d0be3e
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
July 9, 2026 16:41
9e6af76 to
5b5a9b7
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
July 15, 2026 21:32
d3a265e to
c807c58
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
4 times, most recently
from
July 24, 2026 08:48
cd8fe1d to
2a58c6f
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
from
July 30, 2026 07:28
2a58c6f to
a09d88b
Compare
sc-renovate
Bot
force-pushed
the
renovate/npm-lodash-vulnerability
branch
from
July 30, 2026 18:59
a09d88b to
bcdc285
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.17.23→4.18.1lodash vulnerable to Prototype Pollution via array path bypass in
_.unsetand_.omitCVE-2026-2950 / GHSA-f23m-r3pf-42rh
More information
Details
Impact
Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the
_.unsetand_.omitfunctions. The fix for CVE-2025-13465 only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such asObject.prototype,Number.prototype, andString.prototype.The issue permits deletion of prototype properties but does not allow overwriting their original behavior.
Patches
This issue is patched in 4.18.0.
Workarounds
None. Upgrade to the patched version.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
lodash vulnerable to Code Injection via
_.templateimports key namesCVE-2026-4800 / GHSA-r5fr-rjxr-66jc
More information
Details
Impact
The fix for CVE-2021-23337 added validation for the
variableoption in_.templatebut did not apply the same validation tooptions.importskey names. Both paths flow into the sameFunction()constructor sink.When an application passes untrusted input as
options.importskey names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.Additionally,
_.templateusesassignInWithto merge imports, which enumerates inherited properties viafor..in. IfObject.prototypehas been polluted by any other vector, the polluted keys are copied into the imports object and passed toFunction().Patches
Users should upgrade to version 4.18.0.
The fix applies two changes:
importsKeysagainst the existingreForbiddenIdentifierCharsregex (same check already used for thevariableoption)assignInWithwithassignWithwhen merging imports, so only own properties are enumeratedWorkarounds
Do not pass untrusted input as key names in
options.imports. Only use developer-controlled, static key names.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
lodash/lodash (lodash)
v4.18.1Compare Source
Bugs
Fixes a
ReferenceErrorissue inlodashlodash-eslodash-amdandlodash.templatewhen using thetemplateandfromPairsfunctions from the modular builds. See #6167 (comment)These defects were related to how lodash distributions are built from the main branch using https://github.com/lodash-archive/lodash-cli. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.
There is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:
lodash: lodash/lodash@4.18.0-npm...4.18.1-npmlodash-es: lodash/lodash@4.18.0-es...4.18.1-eslodash-amd: lodash/lodash@4.18.0-amd...4.18.1-amdlodash.templatelodash/lodash@4.18.0-npm-packages...4.18.1-npm-packagesv4.18.0Compare Source
v4.18.0
Full Changelog: lodash/lodash@4.17.23...4.18.0
Security
_.unset/_.omit: Fixed prototype pollution viaconstructor/prototypepath traversal (GHSA-f23m-r3pf-42rh, fe8d32e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Nowconstructorandprototypeare blocked unconditionally as non-terminal path keys, matchingbaseSet. Calls that previously returnedtrueand deleted the property now returnfalseand leave the target untouched._.template: Fixed code injection viaimportskeys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800, 879aaa9). Fixes an incomplete patch for CVE-2021-23337. Thevariableoption was validated againstreForbiddenIdentifierCharsbutimportsKeyswas left unguarded, allowing code injection via the sameFunction()constructor sink.importskeys containing forbidden identifier characters now throw"Invalid imports option passed into _.template".Docs
_.templatein threat model and API docs (#6099)lower > upperbehavior in_.random(#6115)_.compactjsdoc (#6090)lodash.*modular packagesDiff
We have also regenerated and published a select number of the
lodash.*modular packages.These modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.