{"id":"CVE-2021-23337","aliases":["CVE-2026-4800","GHSA-35jh-r3h4-6jhm","GHSA-r5fr-rjxr-66jc"],"url":"https://o3.security/vulnerability/CVE-2021-23337","summary":"Command Injection in lodash","details":"Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.","published":"2021-02-15T13:15:12.560Z","modified":"2026-07-08T18:29:35.951751701Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"lodash","fixedVersion":"4.17.21"},{"ecosystem":"npm","name":"lodash-es","fixedVersion":"4.17.21"},{"ecosystem":"npm","name":"lodash.template","fixedVersion":null},{"ecosystem":"npm","name":"lodash-template","fixedVersion":null},{"ecosystem":"RubyGems","name":"lodash-rails","fixedVersion":"4.17.21"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210312-0006/"},{"type":"FIX","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-LODASH-1040724"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T18:29:35.951751701Z"}}