{"id":"CVE-2019-10744","aliases":["GHSA-jf85-cpcp-j695"],"url":"https://o3.security/vulnerability/CVE-2019-10744","summary":"Prototype Pollution in lodash","details":"Versions of `lodash` before 4.17.12 are vulnerable to Prototype Pollution.  The function `defaultsDeep` allows a malicious user to modify the prototype of `Object` via `{constructor: {prototype: {...}}}` causing the addition or modification of an existing property that will exist on all objects.\n\n## Recommendation\n\nUpdate to version 4.17.12 or later.","published":"2019-07-26T00:15:11.217Z","modified":"2026-07-08T05:54:45.347326806Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"lodash","fixedVersion":"4.17.12"},{"ecosystem":"npm","name":"lodash-es","fixedVersion":"4.17.14"},{"ecosystem":"npm","name":"lodash-amd","fixedVersion":"4.17.13"},{"ecosystem":"npm","name":"lodash.defaultsdeep","fixedVersion":"4.6.1"},{"ecosystem":"RubyGems","name":"lodash-rails","fixedVersion":"4.17.12"}],"fix":{"url":"https://github.com/lodash/lodash/pull/4336","label":"lodash/lodash#4336"},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3024"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191004-0005/"},{"type":"ADVISORY","url":"https://support.f5.com/csp/article/K47105354?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-LODASH-450202"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10744"},{"type":"WEB","url":"https://github.com/lodash/lodash/pull/4336"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-10744.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20191004-0005"},{"type":"WEB","url":"https://support.f5.com/csp/article/K47105354?utm_source=f5support&amp;utm_medium=RSS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:45.347326806Z"}}