
🚨 Medium-severity security fix in lodash@4.18.0 just released! Patches CVE-2026-2950 — lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh
Post summary
The tweet announces a medium‑severity patch for lodash that fixes CVE‑2026‑2950, a prototype‑pollution flaw affecting _.unset and _.omit, and includes a link to the vendor advisory.


