CVE-2026-4800General(lodash / lodash)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch lodash lodash systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lodash
  • lodash-amd
  • lodash-es
  • lodash.template

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • General: 8 classified signals
  • Peaked 8d ago at 4 mentions (2026-04-01); latest day: 2
  • 15 total mentions across 10 days

Affected systems

Vendors
Products
lodashlodash-amdlodash-eslodash.template

Deep dive

Activity timeline15 mentions / 10d
01234Mentions · 2026-03-31: 1Mentions · 2026-04-01: 4Mentions · 2026-04-02: 2Mentions · 2026-04-09: 1Mentions · 2026-05-14: 1Mentions · 2026-06-10: 1Mentions · 2026-07-17: 1Mentions · 2026-08-05: 1Mentions · 2026-08-27: 1Mentions · 2026-09-30: 2PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-09-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-02: 1Technical Details · 2026-06-10: 1Technical Details · 2026-07-17: 1Technical Details · 2026-09-30: 103-3104-0104-0204-0905-1406-1007-1708-0508-2709-30
Signal classification3 categories
General
857.1%
Patch
535.7%
PoC
17.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-014
General3PoC1
2026-04-022
General1Patch1
2026-04-091
General1
2026-05-141
General1
2026-06-101
Patch1
2026-07-171
Patch1
2026-08-051
General1
2026-08-271
General1
2026-09-302
Patch1
Full discourse15 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The content is a plain list of CVE identifiers without any additional context or actionable information.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The text lists a large set of CVE identifiers without providing any additional context, technical details, or actionable information.

    30124138.4K
    4.0K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - threalwinky/CVE-2026-4800-POC · GitHub - https://github.com/threalwinky/CVE-2026-4800-POC

    Post summary

    A GitHub repository titled 'CVE-2026-4800-POC' has been shared, indicating that a proof-of-concept for the vulnerability is available.

    140992.2K
    5.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Lodash (CVE-2026-4800) faces an 8.1 CVSS code injection flaw in the _.template function. Attackers can bypass validation via imports. Update to 4.18.0 now! #Lodash #CyberSecurity #JavaScript #NodeJS #InfoSec #Vulnerability #CodeInjection #WebDev #PatchNow https://securityonline.info/lodash-template-code-injection-vulnerability-cve-2026-4800/ https://t.co/Z2DmoIVS8A

    Post summary

    The tweet announces the CVE-2026-4800 code injection flaw in Lodash, provides technical details, and urges users to apply the 4.18.0 patch.

    03062549
    12.3K followersView on X
  • Aikido@AikidoSecurity

    The vulnerability is CVE-2026-4800, CVSS 8.1: code injection through _.template, where unvalidated options.imports keys reach a Function() constructor at compile time. Two related prototype pollution CVEs sit alongside it, 2026-2950 and 2025-13465. The problem is finding it. lodash is rarely a direct dependency anymore. It's pulled in by whatever else you depend on, often through more than one path in your tree, so checking your own package.json won't tell you if you're exposed. Bumping your own pin doesn't touch the copies buried deeper, and each of those needs its own override, with its own risk of breaking something untested.

    11040673
    19.3K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in lodash@4.18.0 just released! Patches CVE-2026-4800 — lodash vulnerable to Code Injection via _.template imports key names https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc

    Post summary

    The post announces that a high‑severity patch for CVE‑2026‑4800 has been released in lodash 4.18.0, detailing a code‑injection flaw via _.template imports and linking to the official GitHub advisory.

    00020209
    5.5K followersView on X
  • Tanya N@Answerislove2
    Patch

    New in our scanners: exact affected lodash-family pins for CVE-2026-4800. Upgrade to 4.18.0+. A version match needs code-path review: risk depends on untrusted _.template imports keys or prototype pollution. Upstream: https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc https://t.co/TI93bmNuUB

    Post summary

    The tweet announces scanner detection for CVE-2026-4800 in lodash, advising users to upgrade to version 4.18.0+ and noting the vulnerability stems from prototype pollution via untrusted _.template imports.

    0001059
    851 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the sam… https://www.cve.org/CVERecord?id=CVE-2026-4800

    Post summary

    The text merely references CVE-2026-4800 and cites a separate fix for CVE-2021-23337, providing no further details or actionable information about the CVE in question.

    00001204
    56.9K followersView on X
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting Lodash (CVE-2026-4800) https://vuldb.com/vuln/354499/cti

    Post summary

    The post reports that more actors have been targeting Lodash CVE‑2026‑4800, but it provides no concrete proof of exploitation, PoC, or remediation details.

    00000114
    2.3K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Storage Manager for ProxMox alert: CVE-2026-4800 (CVSS 8.1) Attackers could disrupt service or cause a denial of service. No workaround is available; follow the vendor advisory for updates. https://vulnipulse.com/advisories/netapp-ntap-20260717-0010 #NetApp #CyberSecurity #CVE

    Post summary

    The post announces a NetApp Storage Manager flaw (CVE‑2026‑4800) with a CVSS score and denial‑of‑service impact, indicates no workaround, and directs users to a vendor advisory for patch updates.

    0000042
    6 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora has released pcs-web-ui version 0.12.2-2 for Fedora 43 and 44 to fix arbitrary code execution flaw CVE-2026-4800 in template imports, according to Linuxsecurity. https://threatcluster.io/cluster/fedora-43-and-44-pcs-code-execution-vulnerabilities-addresse-65327aed

    Post summary

    Fedora has issued a patch (pcs-web-ui 0.12.2-2) to remediate the arbitrary code execution flaw CVE-2026-4800 affecting template imports in Fedora 43 and 44.

    0000063
    318 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-4800: Lodash Template Code Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04bb1rv0

    Post summary

    The snippet references the Lodash Template Code Injection CVE‑2026‑4800 but offers no concrete details on exploitation, patching, or active attacks; it only presents the article title and a link.

    0000037
    28 followersView on X
  • VulnTracker@vuln_tracker
    General

    @piedpiper1616 CVE-2026-4800 proves the imports key was left wide open. Five years between the patches. 200M+ monthly downloads in between. If you're validating template inputs, check imports too. https://vulntracker.io

    Post summary

    The tweet flags that CVE‑2026‑4800 remains widely accessible with many downloads, but offers no deeper technical detail, PoC, or exploitation evidence.

    00000102
    495 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the sam… https://www.cve.org/CVERecord?id=CVE-2026-4800 ----- Traducción: Impacto de CVE-2026-4800: La corrección de… http://infoflow.cloud`

    Post summary

    The post briefly mentions CVE-2026-4800 and cites a related fix for CVE-2021-23337, but offers no PoC, exploit, patch, or technical detail for the new CVE.

    0000044
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-4800 - High Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.... https://www.thehackerwire.com/vulnerability/CVE-2026-4800/ https://t.co/gzYj3hy3xq

    Post summary

    The tweet merely notes the CVE with a high severity tag and links to an external article, offering no technical details, PoC, or patch information.

    0000055
    163 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Applodashlodash-node.js-
Applodashlodash-amd-node.js-
Applodashlodash-es-node.js-
Applodashlodash.template-node.js-

Explore more