CVE-2025-13465Patch(lodash / lodash)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch lodash lodash systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lodash

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-06); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
lodash

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-16: 2Mentions · 2026-03-08: 1Mentions · 2026-04-01: 2Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-16: 2Technical Details · 2026-02-06: 1Technical Details · 2026-02-16: 1Technical Details · 2026-03-08: 1Technical Details · 2026-04-01: 202-0602-1603-0804-01
Signal classification3 categories
Patch
457.1%
General
228.6%
Disclosure
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-062
Patch2
2026-02-162
Patch2
2026-03-081
Disclosure1
2026-04-012
General2
Full discourse7 posts
  • Muzakir@muzakirbloch1
    Disclosure

    Just submitted my FIRST ever bug bounty report on @intigriti! Found a Prototype Pollution vulnerability via Lodash (CVE-2025-13465) — rated Medium severity, currently in Triage #BugBounty #Intigriti #CyberSecurity #Infosec #EthicalHacking #PenTest https://t.co/5cuuaJJj6m

    Post summary

    The user reports a medium‑severity prototype pollution vulnerability in Lodash (CVE‑2025‑13465) submitted as a bug bounty to Intigriti, currently under triage.

    00010157
    1 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just published a deep dive on the critical pgAdmin 4 security update for #Fedora 42 (CVE-2025-13465). It's more than just a "run dnf update" notice. Read more: 👉 https://tinyurl.com/yc5sruwj #Security https://t.co/VBknMP9L2H

    Post summary

    The tweet announces a deep dive into the critical pgAdmin 4 patch for Fedora 42 (CVE‑2025‑13465) and urges users to apply the update.

    0001053
    1.3K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/… https://www.cve.org/CVERecord?id=CVE-2026-2950 ----- Traducción: Impacto de CV… http://infoflow.cloud`

    Post summary

    The post summarizes the CVE-2026-2950 prototype‑pollution issue in Lodash, but provides no PoC, exploit details, active exploitation evidence, or patch information.

    00000268
    65 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/… https://www.cve.org/CVERecord?id=CVE-2026-2950

    Post summary

    The text identifies a prototype pollution vulnerability in Lodash, cites affected versions, and references a CVE record, but offers no further details on PoC, exploit code, active exploitation, or patch.

    00000294
    56.9K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Deep-dive: #SUSE security update for Cockpit (CVE-2025-13465) is out. 🔒 Read more: 👉https://tinyurl.com/mtuszecr #Security https://t.co/6PA2rtusxf

    Post summary

    SUSE has released a security update for Cockpit to address CVE-2025-13465, with the update available via the provided link.

    0000030
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical Patch Alert for #SUSE Linux Enterprise Server 16.0 The SUSE security team has released an urgent update for cockpit-packages to fix CVE-2025-13465, a prototype pollution flaw in the _.unset and _.omit functions. Read more: 👉 https://tinyurl.com/3d8jna9k #Security https://t.co/2UDRHC6pSJ

    Post summary

    SUSE issued a critical patch for CVE‑2025‑13465, a prototype‑pollution flaw in cockpit-packages; no evidence of active exploitation or PoC was provided.

    0000044
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: #Fedora 42 security patch released for yarnpkg prototype pollution vulnerability (CVE-2025-13465). Read more: 👉 https://tinyurl.com/n9yr3rw8 #Security https://t.co/yL6Odt49wu

    Post summary

    Fedora 42 has issued a patch for the yarnpkg prototype‑pollution vulnerability (CVE‑2025‑13465), with no mention of active exploitation or PoC.

    0000047
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applodashlodash-node.js-

Explore more