{"id":"CVE-2026-2950","aliases":["CVE-2025-13465","GHSA-f23m-r3pf-42rh","GHSA-xxjr-mmjv-4gpg"],"url":"https://o3.security/vulnerability/CVE-2026-2950","summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","details":"Impact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prototype properties but does not allow overwriting their original behavior.\n\nPatches:\n\nThis issue is patched in 4.18.0.\n\nWorkarounds:\n\nNone. Upgrade to the patched version.","published":"2026-03-31T19:18:35.796Z","modified":"2026-08-12T03:51:15.847167091Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":{"score":0.00317,"percentile":0.24746,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"lodash","fixedVersion":"4.18.0"},{"ecosystem":"npm","name":"lodash-es","fixedVersion":"4.18.0"},{"ecosystem":"npm","name":"lodash-amd","fixedVersion":"4.18.0"},{"ecosystem":"npm","name":"lodash.unset","fixedVersion":"4.18.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2950.json"},{"type":"ADVISORY","url":"https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2950"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.847167091Z"}}