CVE-2026-2950Disclosure(lodash / lodash)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch lodash lodash systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype. The issue permits deletion of prototype properties but does not allow overwriting their original behavior. Patches: This issue is patched in 4.18.0. Workarounds: None. Upgrade to the patched version.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lodash
  • lodash-amd
  • lodash-es
  • lodash.unset

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-01)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
lodashlodash-amdlodash-eslodash.unset

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 203-3104-01
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-012
Disclosure2
Full discourse3 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in lodash@4.18.0 just released! Patches CVE-2026-2950 — lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh

    Post summary

    The tweet announces a medium‑severity patch for lodash that fixes CVE‑2026‑2950, a prototype‑pollution flaw affecting _.unset and _.omit, and includes a link to the vendor advisory.

    00022174
    5.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/… https://www.cve.org/CVERecord?id=CVE-2026-2950 ----- Traducción: Impacto de CV… http://infoflow.cloud`

    Post summary

    The post discloses a prototype‑pollution vulnerability in Lodash (CVE-2026-2950), detailing affected functions and versions, but offers no link to a PoC, exploit code, patch, or evidence of active exploitation.

    00000268
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2950 Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/… https://www.cve.org/CVERecord?id=CVE-2026-2950

    Post summary

    The post discloses a prototype‑pollution vulnerability in lodash (CVE‑2026‑2950), including affected versions and function names, but offers no PoC, exploit details, or explicit patch instructions.

    00000294
    56.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Applodashlodash-node.js-
Applodashlodash-amd-node.js-
Applodashlodash-es-node.js-
Applodashlodash.unset-node.js-

Explore more